Local Privilege Escalation in OpenLiteSpeed Web Server
CVE-2026-104474

5.4MEDIUM

Key Information:

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104474?

OpenLiteSpeed versions before 1.9.3 are susceptible to a local privilege escalation flaw due to improper handling of update packages in the admin/misc/lsup.sh script. Attackers who compromise the 'nobody' web process can replace the legitimate update package found in the '/usr/local/lsws/autoupdate/' directory. When the auto-update process executes, the malicious install.sh script runs with root privileges, potentially compromising the entire system.

Affected Version(s)

openlitespeed 0 < 1.9.3

openlitespeed 1.9.3

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

FCI Cloud Security
.