CVE-2026-35029Disclosure(litellm / litellm)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch litellm litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-425

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 12 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 3 mentions (2026-09-01); latest day: 1
  • 17 total mentions across 12 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline17 mentions / 12d
01223Mentions · 2026-04-06: 2Mentions · 2026-04-16: 2Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-07: 1Mentions · 2026-09-01: 3Mentions · 2026-09-02: 1Mentions · 2026-09-04: 1Mentions · 2026-09-10: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-09-01: 1PoC Mentioned / Linked · 2026-09-02: 1Active Exploitation · 2026-09-01: 3Active Exploitation · 2026-09-02: 1Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-09-10: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-16: 2Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-09-01: 2Technical Details · 2026-09-10: 1Technical Details · 2026-09-11: 104-0604-1604-2104-2204-3005-0105-0709-0109-0209-0409-1009-11
Signal classification4 categories
Disclosure
741.2%
Active Exploitation
529.4%
Patch
423.5%
General
15.9%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-062
Disclosure1Patch1
2026-04-162
Disclosure1Patch1
2026-04-212
Disclosure1Patch1
2026-04-221
Disclosure1
2026-04-301
Disclosure1
2026-05-011
Disclosure1
2026-05-071
General1
2026-09-013
Active Exploitation3
2026-09-021
Active Exploitation1
2026-09-041
Active Exploitation1
2026-09-101
Disclosure1
2026-09-111
Patch1
Full discourse17 posts
  • zenitylabs@zenitysec_labs
    Active Exploitation

    We've observed attackers began probing LiteLLM's /config/update one day after CVE-2026-35029 was published, and a read-only account was all it took to own the gateway. The endpoints to block, signatures, and IPs, as well as additional related malicious activity. https://t.co/vslRoLNxQX

    Post summary

    Attackers have been probing LiteLLM’s /config/update route following the publication of CVE-2026-35029, with a read‑only account proving sufficient to gain full control of the gateway.

    14070559
    95 followersView on X
  • ET Labs@ET_Labs
    General

    16 new OPEN, 26 new PRO (16 + 10) CVE-2026-35029, Ureq Rust HTTP Client User-Agent, Lumma Stealer, ZPHP, TA569, LandUpdate808, and more. Thanks @PB-22 https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-07-v11188/3282

    Post summary

    The post is a ruleset update from Emerging Threats, listing new CVEs including CVE-2026-35029, but does not provide any further technical, exploit, or patch information.

    02020290
    5.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    Hackers exploit CVE-2026-35029 in the wild. Prevent a LiteLLM vulnerability server takeover and safeguard exposed secrets. #LiteLLM #CVE202635029 #CyberSecurity #AIGateway #ServerTakeover https://securityonline.info/cve-2026-35029-litellm-server-takeover-exploited/

    Post summary

    The post reports that CVE-2026-35029 is actively exploited, enabling LiteLLM server takeover and exposure of secrets, with no mention of a patch or detailed exploit code.

    01020468
    13.0K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-35029 - high 🚨 LiteLLM - Arbitrary File Read > LiteLLM < 1.83.0 contains a broken access control vulnerability caused by lack of adm... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-35029 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑35029 for LiteLLM <1.83.0, describing an access‑control flaw that allows arbitrary file reads, and provides a link to further details without mentioning exploits or patches.

    00012184
    942 followersView on X
  • SEC Consult@sec_consult
    Patch

    ‼️ New advisory: Broken Access Control in @LiteLLM config endpoint (CVE-2026-35029). A missing auth check lets low‑privileged users access sensitive host data via /config/update. Patch available - apply immediately. Full advisory 👉https://r.sec-consult.com/litellm #LLMSecurity #SecureAI

    Post summary

    The advisory highlights a broken access control flaw in LiteLLM’s config endpoint that allows low‑privileged users to access sensitive host data, and it confirms a patch is available and should be applied immediately.

    01010229
    2.5K followersView on X
  • leanroute@leanroute_ai
    Patch

    LiteLLM CVE-2026-35029 landed last week. Read-only viewer -&gt; config-modifier. Patched fast. But it's a good moment to ask: does your team actually have the hours to keep an LLM gateway patched? Wrote up the 5 real alternatives, honest about when to stay: https://leanroute.dev/blog/litellm-alternatives-2026

    Post summary

    CVE‑2026‑35029 was disclosed last week and has been patched quickly; the notice stresses maintaining updated LLM gateways and offers alternative solutions.

    1000047
    1 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    LiteLLMの脆弱性:CVE-2026-35029、サイバー攻撃の悪用確認  https://rocket-boys.co.jp/security-measures-lab/litellm-cve-2026-35029-alert/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The article confirms that CVE-2026-35029 in LiteLLM is being actively exploited in cyber attacks, but provides no further technical details or mitigation information.

    00010147
    625 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The vulnerability exists because the update_config function, which handles the /config/update route, does not check whether the requesting user has administrative permissions.』 CVE-2026-35029 Broken Access Control in Config Endpoint in LiteLLM https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-config-endpoint-in-litellm/

    Post summary

    The advisory identifies a broken access control in LiteLLM’s /config/update endpoint where administrative privileges are not validated.

    01000485
    6.8K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    LiteLLM、認証回避とRCEにつながる複数の重大脆弱性を修正(CVE-2026-35030,CVE-2026-35029) https://rocket-boys.co.jp/security-measures-lab/litellm-multiple-flaws-fixed-auth-bypass-rce/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    LiteLLM has addressed two critical CVEs (CVE‑2026‑35030 and CVE‑2026‑35029) involving authentication bypass and remote code execution, as noted in the linked article, indicating that patches have been deployed.

    0000178
    380 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    LiteLLM Admin API の脆弱性 CVE-2026-35029:読み取り専用アクセスからサーバー全体の乗っ取りへ https://iototsecnews.jp/2026/09/02/hackers-exploit-litellm-admin-api-flaw-to-turn-read-only-access-into-full-server-takeover/ AI ゲートウェイ製品 LiteLLM に存在する脆弱性 CVE-2026-35029 の認可チェック不備を紹介する記事です。認証制御の欠落に伴う設定の不正変更/ローカルファイルの読み取り/管理者権限の奪取という連鎖的な影響が確認されています。本件の背景には管理エンドポイントにおける権限検証の不足があり、低権限アクセスからインフラ全体へ被害が拡大する恐れがあります。システム管理運用においては バージョン 1.83.0 以降へのアップデート/漏洩した認証情報の更新/コントロールプレーンへのアクセス制御強化/監視の徹底が強く求められます。 #CVE202635029 #LiteLLM #Vulnerability

    Post summary

    The post announces a privilege‑escalation flaw in LiteLLM’s Admin API (CVE‑2026‑35029), details how missing auth checks enable unauthorized changes and full server takeover, and recommends patching to v1.83.0 and other mitigations.

    00000133
    514 followersView on X
  • moton@moton
    Active Exploitation

    CVE-2026-35029 Exploited for Full Server Takeover - https://securityonline.info/cve-2026-35029-litellm-server-takeover-exploited/

    Post summary

    The CVE-2026-35029 is reported as actively exploited for full server takeover, with no patch, tool, or technical details disclosed in the brief text.

    0000079
    755 followersView on X
  • Avishai Efrat@avishai_efrat
    Active Exploitation

    We've observed attackers began probing LiteLLM's /config/update one day after CVE-2026-35029 was published, and a read-only account was all it took to own the gateway. The endpoints to block, signatures, and IPs, and related malicious activity: https://labs.zenity.io/post/admin-api-escalation-litellm

    Post summary

    After CVE‑2026‑35029 was published, attackers have been probing LiteLLM's /config/update endpoint and exploiting a privilege escalation that lets a read‑only account take full control of the gateway.

    0000082
    281 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-35029: LiteLLM Flaw Allows RCE via Config Endpoint https://thecybrdef.com/cve-2026-35029-litellm-flaw-allows-rce-via-config-endpoint/

    Post summary

    The text announces that CVE‑2026‑35029 in LiteLLM enables remote code execution through a configuration endpoint, but it provides no further details on PoC, exploitation, or remediation.

    0000028
    4 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-35029: LiteLLM Flaw Allows RCE via Config Endpoint https://thecybrdef.com/cve-2026-35029-litellm-flaw-allows-rce-via-config-endpoint/

    Post summary

    The text announces a new RCE vulnerability (CVE‑2026‑35029) in LiteLLM’s configuration endpoint, providing only basic technical details without reference to PoC, exploit code, active exploitation or patch.

    0000024
    8 followersView on X
  • Armor1@armor1_ai
    Disclosure

    CVE-2026-35029, CVSS 8.7: /config/update endpoint (admin-only in design) was accessible to any authenticated user. Accepts Python handler registration. Chain with 35030: admin impersonation -&gt; register malicious handler -&gt; arbitrary code execution on the LiteLLM proxy.

    Post summary

    The text reports that CVE-2026-35029 allows any authenticated user to access the /config/update endpoint, register malicious Python handlers, and combined with CVE-2026-35030 can lead to arbitrary code execution on the LiteLLM proxy. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000041
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35029 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authori… https://www.cve.org/CVERecord?id=CVE-2026-35029

    Post summary

    The post notes a missing admin role check on LiteLLM’s /config/update endpoint in pre‑1.83.0 releases, indicating a vulnerability but provides no PoC, exploit, or remediation details.

    00000189
    57.0K followersView on X
  • TheDarkForge@DarkForgeNews
    Patch

    [CYBERSEC] 𝗟𝗶𝘁𝗲𝗟𝗟𝗠 𝗣𝗮𝘁𝗰𝗵𝗲𝘀 𝗣𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 𝗘𝘀𝗰𝗮𝗹𝗮𝘁𝗶𝗼𝗻 𝗙𝗹𝗮𝘄 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟯𝟱𝟬𝟮𝟵 𝗶𝗻 𝗩𝗲𝗿𝘀𝗶𝗼𝗻 𝟭.𝟴𝟯.𝟬 LiteLLM patched CVE-2026-35029, a privilege escalation vulnerability in its /config/update endpoint that lacked admin role authorization, in version 1.83.0, according to the LiteLLM Security Blog. Any holder of a valid API key could exploit the flaw to modify proxy configuration without elevated permissions. The fix arrived roughly one week after a March 2026 supply chain incident in which TeamPCP compromised Trivy, an open-source security scanner used in LiteLLM's CI/CD pipeline, compressing the window between external threat and internal disclosure. Veria Labs independently audited the patch. The /config/update endpoint accepted configuration changes from any authenticated request regardless of the caller's role — an authorization gap that effectively handed proxy-level control to any valid API key holder. LiteLLM's security team bundled the fix with patches for additional high-severity vulnerabilities in the 1.83.0 release, though the blog did not enumerate those CVEs individually. The March 2026 supply chain compromise, in which a malicious actor compromised Trivy used in LiteLLM's CI/CD pipeline, preceded this disclosure and likely accelerated the internal audit that surfaced CVE-2026-35029. Veria Labs confirmed the authorization controls were correctly implemented post-patch. What remains unclear: whether any exploitation of CVE-2026-35029 occurred prior to the 1.83.0 release, the full scope of the additional high-severity vulnerabilities patched alongside it, and the relationship — if any — between the March 2026 supply chain incident and the discovery timeline for this specific flaw. — 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗘'𝗦 𝗪𝗘𝗜𝗚𝗛𝗧 An endpoint that modifies proxy configuration existed without role gating — not as a temporary oversight caught in review, but as shipped behavior that required an external audit to surface. The March supply chain incident and this authorization gap are unrelated in mechanism but identical in what they reveal: the security perimeter of a widely-used AI infrastructure tool was being defined reactively, after exposure, not before it. The open question is how many other endpoints were reviewed only because a scanner got poisoned. 𝘚𝘰𝘶𝘳𝘤𝘦𝘴: 𝘓𝘪𝘵𝘦𝘓𝘓𝘔 𝘚𝘦𝘤𝘶𝘳𝘪𝘵𝘺 𝘉𝘭𝘰𝘨 | 𝘝𝘦𝘳𝘪𝘢 𝘓𝘢𝘣𝘴

    Post summary

    LiteLLM announces a privilege‑escalation vulnerability (CVE‑2026‑35029) in its /config/update endpoint and releases a patch in v1.83.0, but provides no evidence of exploitation or PoC.

    0000047
    21 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more