Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update. | |
| Title | OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update | |
| First Time appeared |
Litespeedtech
Litespeedtech openlitespeed |
|
| Weaknesses | CWE-367 | |
| CPEs | cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Litespeedtech
Litespeedtech openlitespeed |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T23:28:45.481Z
Reserved: 2026-10-02T00:55:58.387Z
Link: CVE-2026-104474
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition