MEDIUM
OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
Published Oct 3, 2026
5.4
MEDIUMCVSS 4.0
EPSS 0.08%
Description
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Affected products
-
Affected
- ≥ 0, < 1.9.3
Unaffected
- 1.9.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Litespeedtech | Openlitespeed | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91850 Advisory
- https://github.com/litespeedtech/openlitespeed/blob/v1.9.2/dist/admin/misc/lsup.sh#L538 technical-description
- https://github.com/litespeedtech/openlitespeed/commit/468523ce84388cea9ba6633c26517bc05b3e2bc1 patch
- https://openlitespeed.org/release-log/version-1-9-x/ vendor-advisory
- https://www.vulncheck.com/advisories/openlitespeed-before-1.9.3-local-privilege-escalation-via-lsup-sh-auto-update third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Oct 3, 2026
Updated Oct 5, 2026
Reserved Oct 2, 2026
Link CVE-2026-104474
CISA Vulnrichment
Updated Oct 5, 2026
Red Hat
No data
GitHub
No data