CVE-2026-31386EPSS p71.2%

CVE-2026-31386CVE-2026-31386

litespeedtech / litespeed_web_server

Description

OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

Scoring

CVSS 7.2 ()
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS1.51% probability of exploitation · percentile 71.2% · 2026-06-18T12:00:27Z
Last modified2026-06-08

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-33277
CVE
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
CVE
CVE-2026-22550
CVE
CVE-2026-24663
CVE
TP-Link Archer AX-21 Command Injection Vulnerability
CVE
CVE-2026-23702
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.