QSearchQSearch

CVE-2026-31386

7.2 HIGH

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability

Published: 2026-03-16 · Last updated: 2026-06-08

Severity and scoring

CVSS
7.2 HIGH
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78

Affected products

VendorProduct
litespeedtechlitespeed_web_server, openlitespeed

Description

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-48172 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026 (9.8 CRITICAL)

Same CWE

  • CVE-2026-42846 ClipBucket v5 is an open source video sharing platform (9.8 CRITICAL)
  • CVE-2026-45172 Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0....
  • CVE-2026-48547 KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands ... (7.3 HIGH)
  • CVE-2026-49261 MariaDB server is a community developed fork of MySQL server (10.0 CRITICAL)
  • CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)