jvn.jp
https://jvn.jp/en/jp/JVN22152812 CVE-2026-31386
HIGH
LiteSpeed Technologies LSWS Enterprise and OpenLiteSpeed OS Command Injection
Record summary
CVE-2026-31386 has a selected CVSS score of 8.6 (high).
Description
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 16, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
LSWS EnterpriseBrowse LiteSpeed Technologies / LSWS Enterprise | CVE List | all versions | affected |
OpenLiteSpeedBrowse LiteSpeed Technologies / OpenLiteSpeed | CVE List | all versions | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-31386 openlitespeed.org
https://openlitespeed.org/ litespeedtech.com
https://www.litespeedtech.com/products/litespeed-web-server