CVE-2026-104474

CVE-2026-104474 published: OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/...

View full NVD advisory → ← Back to CVE watch