Zurück zu den Sicherheitshinweisen

LiteSpeed CVE-2026-93903

CVE-2026-93903 is a vulnerability in LiteSpeed Web Server builds before 6.3.7 build 1, where internal redirect URL validation is mishandled in a certain corner case. NVD rates it Critical with a CVSS 3.1 base score of 9.4. Anyone running an affected LiteSpeed Web Server build should update to 6.3.7 build 1 or later.

Critical 9.4 CVSS
LiteSpeed

Was das unter einer SharedLicense-Lizenz bedeutet

Because redirect URL validation fails in an edge case, an attacker may be able to reach internal targets through crafted requests; the full exploitability window is described only as a corner case by NVD.

LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain “corner case.”

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-93903

Häufig gestellte Fragen

What is CVE-2026-93903?
It is the CVE ID for a flaw in LiteSpeed Web Server before 6.3.7 build 1 that mishandles internal redirect URL validation in a certain corner case. NVD assigns it CWE-174 (Interpretation Conflict) and a CVSS base score of 9.4.
Which LiteSpeed versions are affected?
LiteSpeed Web Server builds before 6.3.7 build 1 are affected. Builds at 6.3.7 build 1 or later contain the fix — this matches the DirectAdmin forum's separate advice that Enterprise 6.3.7 or later is required.
How do I fix CVE-2026-93903?
Update LiteSpeed Web Server Enterprise to 6.3.7 build 1 or later through your normal LiteSpeed update channel (or the WHM LiteSpeed plugin if installed), then confirm the running build in the LiteSpeed Web Admin console.
Is CVE-2026-93903 being exploited in the wild?
No confirmed exploitation has been announced, and NVD has not recorded exploit intelligence for this CVE yet. Given the critical rating, patch on a priority basis rather than waiting.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen