CVE-2026-31386Disclosure(litespeedtech / litespeed_web_server)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch litespeedtech litespeed_web_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litespeed_web_server
  • openlitespeed

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-16); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
litespeed_web_serveropenlitespeed

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-16: 3Mentions · 2026-03-17: 2Mentions · 2026-06-08: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 2Technical Details · 2026-06-08: 103-1603-1706-08
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-163
Disclosure3
2026-03-172
Disclosure1Patch1
2026-06-081
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    An 8.6 CVSS flaw (CVE-2026-31386) in LiteSpeed Web Server editions allows OS command injection and system compromise. Restrict WebAdmin access immediately. #LiteSpeed #CVE #ServerSecurity #CyberSecurity #InfoSec #CommandInjection #WebHosting #OpenLiteSpeed https://securityonline.info/server-siege-critical-8-6-cvss-flaw-litespeed-web-server-os-command-injection/ https://t.co/92Ga1u2QgT

    Post summary

    The post announces a high‑severity OS command injection flaw (CVE‑2026‑31386) in LiteSpeed Web Server, providing basic technical details and a recommended workaround.

    03040453
    10.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة عالية الخطورة تهدد خوادم LiteSpeed Web Server عبر حقن (OS Command Injection) أصدرت JPCERT/CC تحذيراً أمنياً حرجاً بشأن ثغرة عالية الخطورة (CVSS 8.6) في خوادم الويب LiteSpeed Web Server، البديل الشائع لخادم Apache. تستغل هذه الثغرة، المحددة بـ CVE-2026-31386 و CVE-2026-26954، ضعفاً في حقن أوامر نظام التشغيل (OS Command Injection). يتيح هذا الضعف للمهاجمين تنفيذ تعليمات برمجية عن بُعد على الخوادم المستهدفة، مما قد يؤدي إلى السيطرة الكاملة عليها. يُنصح بشدة لمسؤولي الأنظمة بتطبيق التحديثات الأمنية فوراً للتخفيف من مخاطر الاستغلال المحتملة. 🔗 للمزيد: https://securityonline.info/server-siege-critical-8-6-cvss-flaw-litespeed-web-server-os-command-injection/

    Post summary

    The post announces a high‑severity OS Command Injection in LiteSpeed Web Server, provides technical details and urges immediate patching, but does not mention PoCs or active exploitation.

    00030468
    71 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenLiteSpeed / LSWS Enterprise, #OS Command Injection, #CVE-2026-31386 (Critical) -DC-Jun2026-253 https://dailycve.com/openlitespeed-lsws-enterprise-os-command-injection-cve-2026-31386-critical-dc-jun2026-253/

    Post summary

    An OpenLiteSpeed LSWS Enterprise CVE-2026-31386, a critical OS command injection vulnerability, has been disclosed; no proof‑of‑concept, exploit, or patch details are provided in the snippet.

    0000047
    210 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    LiteSpeed Web Serverに高深刻度のOSコマンドインジェクションの脆弱性(CVE-2026-31386) https://rocket-boys.co.jp/security-measures-lab/litespeed-web-server-os-command-injection-cve-2026-31386/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    A new OS command injection vulnerability (CVE‑2026‑31386) affecting LiteSpeed Web Server is disclosed, highlighting its high severity, but no PoC, exploitation details, or patch is provided.

    00000120
    336 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31386 OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an atta… https://www.cve.org/CVERecord?id=CVE-2026-31386 ----- Traducción: CVE-2026-31386 Ope… http://infoflow.cloud`

    Post summary

    OpenLiteSpeed and LSWS Enterprise are affected by CVE-2026-31386, an OS command injection vulnerability that could allow attackers to execute arbitrary OS commands.

    0000037
    58 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31386 OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an atta… https://www.cve.org/CVERecord?id=CVE-2026-31386

    Post summary

    The announcement reveals CVE-2026-31386 as an OS command injection flaw in OpenLiteSpeed and LSWS Enterprise that permits arbitrary command execution.

    00000294
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Applitespeedtechlitespeed_web_server---
Applitespeedtechopenlitespeed---

Explore more