


Perceptive Security
SOC/SIEM Consultancy

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated admiā¦
Published:
22 January 2026 at 23:00:00
Alert date:
23 January 2026 at 18:06:58
Source:
nvd.nist.gov
Web Technologies
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration. The vulnerability allows remote code execution via path traversal and bash command injection. This affects the external application configuration functionality of the web server. The vulnerability requires administrative authentication to exploit. Multiple references and exploit code are available for this CVE.
Technical details
Mitigation steps:
Affected products:
LiteSpeed Web Server Enterprise
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2021-47903
https://www.exploit-db.com/exploits/49523
https://www.litespeedtech.com/
https://www.litespeedtech.com/products
https://www.vulncheck.com/advisories/litespeed-web-server-enterprise-command-injection
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
