CVE-2026-104474 PUBLISHED

OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 5.4

Product Status

Vendor litespeedtech
Product openlitespeed
Versions Default: unaffected
  • affected from 0 to 1.9.3 (excl.)
  • Version 1.9.3 is unaffected

Credits

  • FCI Cloud Security finder

References

Problem Types

  • Time-of-check Time-of-use (TOCTOU) Race Condition CWE