Local Privilege Escalation in OpenLiteSpeed Web Server
CVE-2026-104474
5.4MEDIUM
What is CVE-2026-104474?
OpenLiteSpeed versions before 1.9.3 are susceptible to a local privilege escalation flaw due to improper handling of update packages in the admin/misc/lsup.sh script. Attackers who compromise the 'nobody' web process can replace the legitimate update package found in the '/usr/local/lsws/autoupdate/' directory. When the auto-update process executes, the malicious install.sh script runs with root privileges, potentially compromising the entire system.
Affected Version(s)
openlitespeed 0 < 1.9.3
openlitespeed 1.9.3
