CVE & Vulnerabilities · October 6, 2026
A newly tracked flaw, CVE-2026-104474, affects OpenLiteSpeed versions before 1.9.3, where the admin update script runs packages from a directory writable by the low-privileged 'nobody' account but executes the installer as root. An attacker who has already compromised the web server process could swap in a malicious update package, letting it escalate straight to root the next time an update runs. The issue highlights how a routine auto-update mechanism can become a full local privilege-escalation path.
// source: nvd.nist.gov ↗