Record summary

CVE-2026-31386 has a selected CVSS score of 8.6 (high).

Description

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 16, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listall versionsaffected
CVE Listall versionsaffected

References

4