CVE-2026-93903: Update LiteSpeed Web Server prior to 6.3.7 build 1
This text was generated using artificial intelligence (AI).CVE-2026-93903 affects LiteSpeed Web Server before 6.3.7 build 1. According to LiteSpeed Technologies, the web server incorrectly handles the validation of internal redirect URLs in a specific edge case. This allows a malicious website user to bypass account isolation, including CageFS.
The vendor provides the fix in LiteSpeed Web Server Enterprise 6.3.7 build 1 . The fix was made available on September 16, 2026; the CVE was documented on September 30, 2026.
Active Exploitation: As of now, there is no known active exploitation of CVE-2026-93903.
Faulty validation of internal redirect URLs
The vulnerability is classified as CWE-174: Double Decoding of the Same Data classified. LiteSpeed Web Server processes the validation of internal redirect URLs incorrectly in the case of CVE-2026-93903. A malicious website user can thus bypass the intended separation of accounts, including CageFS.
For environments with multiple customer accounts, this impact is particularly relevant as account isolation creates a technical boundary between accounts. Therefore, the patch status of the web server should be checked promptly.
Perform Upgrade and Check Installation
LiteSpeed Technologies recommends upgrading to LiteSpeed Web Server Enterprise 6.3.7 build 1 or a later version. The vendor provides the following update command:
/usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7
Automatic updates should not be the only update measure, as their deployment may be delayed.
After the upgrade, the following checks are part of the process:
Check installed version and build number, for example with cat lsws/BUILD.
Investigate the server for unusual CGI activities or piped logging behavior.
Ensure that server-side logging continues to function properly after the update.
Maintain the patch status in regular vulnerability and vendor monitoring.
The version and build check confirms whether the cleaned version was actually installed. Checking the logging supports operational monitoring after the update.
Shared hosting providers in Germany and Austria using LiteSpeed Web Server may be subject to the GDPR reporting obligation under Art. 33 (72-hour deadline to the competent authority) in the event of a successful attack with access to personal data. NIS-2 obligated operators in Germany and Austria should document the patch status as part of their vulnerability management. In Switzerland, the reporting obligation to BACS applies according to the revised Information Security Act (ISG).
Externally accessible LiteSpeed systems capture
LocateRisk makes publicly accessible systems and software in use visible. This allows LiteSpeed web servers in one's own externally accessible infrastructure to be identified and prioritized for patch testing — including forgotten subdomains, neglected cloud assets, or non-inventoried systems in the area of responsibility.
The external detection of a LiteSpeed system does not replace a check of the installed version and build number on the server. For CVE-2026-93903, this check remains critical to evaluate the update status against the cleaned version 6.3.7 build 1.
In Vendor Risk Management, reports of critical vulnerabilities in technology providers can be incorporated into the ongoing evaluation of suppliers and dependencies. EASM supports visibility of publicly accessible systems in one's own area of responsibility.
Am I affected?
This affects LiteSpeed Web Server in the versions mentioned above; the vulnerability was fixed in 6.3.7 build 1. If you want to know whether LiteSpeed Web Server is even visible in your own externally accessible infrastructure, you can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-93903 is a vulnerability in LiteSpeed Web Server (LSWS) before version 6.3.7 build 1. The server incorrectly handles the validation of internal redirect URLs in a specific edge case (CWE-174: Double Decoding of the Same Data), allowing a malicious website user to bypass account isolation including CageFS on shared hosting servers. The vulnerability is rated as 9.4 (CVSS 4.0) critical.
All versions of LiteSpeed Web Server prior to 6.3.7 build 1 are affected. The cleaned version is 6.3.7 build 1. The currently installed build number can be checked with the command cat lsws/BUILD check. An upgrade is possible with /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 feasible.
As of now, there is no known active exploitation of CVE-2026-93903. However, an upgrade to 6.3.7 build 1 is recommended as the vulnerability affects account isolation in shared hosting environments and the CVSS score is rated as critical at 9.4.
As of: September 30, 2026. This contribution serves general informational purposes and is not legal, security, or action advice for individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we accept no liability for the timeliness, accuracy, or completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-93903
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.