logo

High-Severity Flaw Exposes LiteSpeed Web Servers to OS Command Injection

ID: 9e460aaa-5f33-5b76-b287-f014635b5617

STIX ID: report--9e460aaa-5f33-5b76-b287-f014635b5617

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical OS command injection vulnerability (CVE-2026-31386, CVSSv4 8.6) has been disclosed in the LiteSpeed Web Server WebAdmin console (affecting open-source and enterprise editions). An attacker with administrative privileges may execute arbitrary operating-system commands, risking privilege escalation and lateral movement across hosting environments; vendor guidance recommends restricting WebAdmin network access, IP whitelisting, requiring VPNs for admin access, and monitoring administrative logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.