Junglewise Threat Intelligence

CVE-2026-31386: LiteSpeed Technologies OpenLiteSpeed and LSWS Enterprise OS command injection

CVE-2026-31386 · Severity: high · CVSS 7.2 · Published 2026-03-16

Executive brief

LiteSpeed Technologies' OpenLiteSpeed and LSWS Enterprise web servers, which are used to host high-performance websites, contain a vulnerability that allows an administrator to execute unauthorized system commands. If exploited, an attacker with administrative access could take full control of the underlying server, potentially leading to data theft or service disruption. Organizations should restrict access to the WebAdmin console to trusted IP addresses and update to the latest software versions.

Technical details

An OS command injection vulnerability (CWE-78) exists in LiteSpeed Technologies' OpenLiteSpeed (up to 1.9.0) and LSWS Enterprise (up to 6.3.4). The flaw resides within the WebAdmin console, where improper neutralization of special elements allows an attacker with high privileges (administrative access) to execute arbitrary OS commands via the network. While the attack requires authentication, successful exploitation results in full compromise of the host system (High Confidentiality, Integrity, and Availability impact). A workaround involves restricting access to the WebAdmin console port and implementing IP-based access control lists. Fixed versions include LSWS Enterprise 6.3.5.

Affected products

  • LiteSpeed Technologies OpenLiteSpeed up to and including 1.9.0
  • LiteSpeed Technologies LiteSpeed Web Server Enterprise up to but excluding 6.3.5

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory

References