{"id":"CVE-2021-26758","details":"Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.","modified":"2026-07-09T00:13:11.972818Z","published":"2021-04-07T21:15:16.090Z","references":[{"type":"EVIDENCE","url":"https://docs.unsafe-inline.com/0day/openlitespeed-web-server-1.7.8-command-injection-to-privilege-escalation-cve-2021-26758"},{"type":"EVIDENCE","url":"https://github.com/litespeedtech/openlitespeed/issues/217"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/49556"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/litespeedtech/openlitespeed","events":[{"introduced":"f7f66a3c2bdbdd6b57ef8582e64c1921f5a9ee7c"},{"last_affected":"f7f66a3c2bdbdd6b57ef8582e64c1921f5a9ee7c"}],"database_specific":{"extracted_events":[{"introduced":"1.7.8"},{"last_affected":"1.7.8"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:litespeedtech:openlitespeed:1.7.8:*:*:*:*:*:*:*"}}],"versions":["1.7.8","v1.7.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26758.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}