{"id":"CVE-2026-104474","summary":"OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update","details":"OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.","modified":"2026-10-04T07:03:19.590595Z","published":"2026-10-02T23:28:45.481Z","database_specific":{"cwe_ids":["CWE-367"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104474.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104474.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104474"},{"type":"ADVISORY","url":"https://openlitespeed.org/release-log/version-1-9-x/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openlitespeed-before-1.9.3-local-privilege-escalation-via-lsup-sh-auto-update"},{"type":"FIX","url":"https://github.com/litespeedtech/openlitespeed/commit/468523ce84388cea9ba6633c26517bc05b3e2bc1"},{"type":"PACKAGE","url":"https://github.com/litespeedtech/openlitespeed"},{"type":"ARTICLE","url":"https://github.com/litespeedtech/openlitespeed/blob/v1.9.2/dist/admin/misc/lsup.sh#L538"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/litespeedtech/openlitespeed","events":[{"introduced":"0"},{"fixed":"bf584c1b7cd6edd5dacfffaad477bcb67d65d732"},{"fixed":"468523ce84388cea9ba6633c26517bc05b3e2bc1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.9.3"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v1.9.2","v1.9.1","v1.9.0.1","v1.9.0","broken_modsec","v1.8.1","v1.8.0","v1.7.17","v1.7.10.2","v1.7.10.1","v1.7.10","v1.7.9.2","v1.7.9.1","v1.7.9","v1.7.8","v1.7.7","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.3","v1.5.2","v1.5.0","v1.5.0rc6","v1.4.2","v1.4.1","v1.4.0","v1.3.2","v1.3","v1.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104474.json","vanir_signatures_modified":"2026-10-04T07:03:19Z","vanir_signatures":[{"target":{"file":"src/http/requestvars.cpp","function":"RequestVars::setEnv"},"deprecated":false,"digest":{"function_hash":"2125362203580197755792326805685250372","length":1971},"id":"CVE-2026-104474-3ea6d0b9","signature_type":"Function","signature_version":"v1","source":"https://github.com/litespeedtech/openlitespeed/commit/bf584c1b7cd6edd5dacfffaad477bcb67d65d732"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["322848671198276622123071718230853437515","137521964143416189227387714904764673259","37555269937062941136775005567498507725","53079506554068539713271537603646810771"]},"id":"CVE-2026-104474-689ec833","signature_type":"Line","signature_version":"v1","source":"https://github.com/litespeedtech/openlitespeed/commit/bf584c1b7cd6edd5dacfffaad477bcb67d65d732","target":{"file":"src/http/requestvars.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}