CVE-2026-31386 PUBLISHED

Assigner: jpcert
Reserved: 09.03.2026 Published: 16.03.2026 Updated: 16.03.2026

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor LiteSpeed Technologies
Product OpenLiteSpeed
Versions
  • Version all versions is affected
Vendor LiteSpeed Technologies
Product LSWS Enterprise
Versions
  • Version all versions is affected

References

Problem Types