OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93903

CRITICAL · CVSS 9.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

LiteSpeed Web Server versions prior to 6.3.7 build 1 are vulnerable due to improper validation of internal redirect URLs, which could be exploited to conduct unauthorized actions or access sensitive information. This critical vulnerability, rated 9.4 on the CVSS scale, poses a significant risk to web applications relying on LSWS for their operations. Organizations using affected versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-93903
Severity
CRITICAL
CVSS
9.4
EPSS
0.26%

Original NVD Description

LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."