Description
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Published: 2026-10-02
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

OpenLiteSpeed before 1.9.3 has a flaw in the admin/misc/lsup.sh script that allows an attacker controlling the web process running as the nobody user to substitute an update package in the /usr/local/lsws/autoupdate/ directory. The script then extracts and executes the install.sh component as root, giving the attacker full system privileges without authentication. This vulnerability exposes the server to complete control over the operating system and any services running on it.

Affected Systems

The affected product is OpenLiteSpeed from LiteSpeed Technologies, in all releases prior to version 1.9.3. The vulnerability is present whenever the auto‑update directory is writable by the nobody user and the unverified install.sh script is executed as root during a normal update cycle.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity, and the EPSS score is not available, suggesting no recent exploitation data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker who can run code as the nobody web process can replace the update package, which then runs with root permissions during the next update. Because the flaw requires local access to the web server, it is contingent on successful compromise of the web-facing component, but once achieved it provides full administrator privileges.

Generated by OpenCVE AI on October 3, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading OpenLiteSpeed to version 1.9.3 or later, which removes the unsafe execution of update packages.
  • Disable the automatic update mechanism or change the permissions on /usr/local/lsws/autoupdate/ so that only root can write or execute files within that directory.
  • Ensure that any remaining update scripts are run only by root and that the nobody user has no write permissions to directories containing privileged scripts.

Generated by OpenCVE AI on October 3, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Title OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
First Time appeared Litespeedtech
Litespeedtech openlitespeed
Weaknesses CWE-367
CPEs cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*
Vendors & Products Litespeedtech
Litespeedtech openlitespeed
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Litespeedtech Openlitespeed
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:45.481Z

Reserved: 2026-10-02T00:55:58.387Z

Link: CVE-2026-104474

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T00:16:35.413

Modified: 2026-10-03T00:16:35.413

Link: CVE-2026-104474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:30:19Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition