CVE-2026-104474: OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenLiteSpeedto a version that resolves this vulnerability.Fixed in 1.9.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs control of the nobody web process, allowing them to replace an update package in /usr/local/lsws/autoupdate/. This is a local privilege-escalation issue rather than a remote unauthenticated attack.
What must happen for the privilege escalation to occur?
After the attacker replaces the package, the OpenLiteSpeed update process must run. During the next update, lsup.sh extracts the unverified package and executes its install.sh script as root.
Which installations are affected?
OpenLiteSpeed versions before 1.9.3 are affected where the auto-update workflow uses the vulnerable lsup.sh behavior and the attacker can control the nobody web process.
What is the immediate mitigation if upgrading is not possible?
Prevent untrusted control of the nobody web process and protect the contents of /usr/local/lsws/autoupdate/ from modification by that process. Avoid running the vulnerable update workflow until the package cannot be replaced.