CVE-2026-104474

Summary

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.

Affected Software

VendorProductVersion RangeStatus
litespeedtechopenlitespeed0 < 1.9.3affected
litespeedtechopenlitespeed1.9.3unaffected

Weaknesses

  • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition

References