Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104474— OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update

Quick assessment

Affected
litespeedtech openlitespeed
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenLiteSpeed 在 1.9.3 版本之前存在一个本地权限提升漏洞,该漏洞位于 admin/misc/lsup.sh 脚本中。该脚本以 root 身份从 nobody 用户可写的目录中执行未经验证的更新包。攻击者若控制了 nobody 身份的 Web 进程,可以在文件解包前替换 /usr/local/lsws/autoupdate/ 目录中的更新包,从而使后续的 install.sh 脚本以 root 权限执行。

CVSS 6.7 · Medium EPSS 0.08% · P0

Affected Version Matrix 2

VendorProduct Version RangeStatus
litespeedtech openlitespeed < 1.9.3 affected
1.9.3 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
Source: CVE Program / CVE List V5
Vulnerability Description
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
litespeedtech openlitespeed 0 ~ 1.9.3 -

II. Public POCs for CVE-2026-104474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104474

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104474 (1)

Vendor Advisories for CVE-2026-104474 (1)

Vendor Pages for CVE-2026-104474 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104474

No comments yet


Leave a comment