CVE-2026-47101Disclosure(litellm / litellm)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch litellm litellm systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-16); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-05-22: 1Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-06-18: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Exploit Tool / Code · 2026-06-16: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-06-17: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-16: 2Technical Details · 2026-06-17: 1Technical Details · 2026-06-18: 1Technical Details · 2026-08-11: 105-2206-1606-1706-1808-1108-12
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
General
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-221
Disclosure1
2026-06-162
Disclosure1Patch1
2026-06-171
Patch1
2026-06-181
Disclosure1
2026-08-111
General1
2026-08-121
General1
Full discourse7 posts
  • Miggo Security@MiggoSecurity
    General

    Attackers rarely need one devastating flaw. They need a sequence of small ones, each unlocking the next. CVE-2026-47101, CVE-2026-47102, CVE-2026-40217: a low-privilege token widened, access escalated to admin, code execution reaching the host. Two layers stopped it: ▪️WAF Copilot blocked the privilege escalation at the edge. ▪️The runtime sensor identified and blocked the code execution inside the app, before a CVE existed for it. Miggo Head of Architecture, Ben Stav, walks through the full chain, with equal parts technical rigor and few quirky memes. https://www.miggo.io/post/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache

    Post summary

    The post discusses a sequence of low‑privilege CVEs, the defensive layers that stopped them, and provides technical detail but no PoC, exploit code, or active exploitation report.

    0002067
    142 followersView on X
  • Davin Jackson@Djax_Alpha
    General

    Defense-in-Depth in Action: How to Stop the LiteLLM Chain (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) with Panache https://api.cyfluencer.com/s/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache-28947/1

    Post summary

    The brief title and link reference hint at defensive guidance regarding three CVEs, but no concrete technical details, PoC, or mitigation information are provided.

    00010289
    9.1K followersView on X
  • NewsTongue@NewsTongueX
    Disclosure

    🔴 Four AI tools broke same way in two weeks: prompt injection, privilege escalation, path traversal Varonis disclosed SearchLeak (CVE-2026-42824) on June 15—a silent exfiltration chain in Microsoft 365 Copilot Enterprise Search. A crafted URL triggers Copilot to search a victim's mailbox and leak data through a Bing SSRF with no user interaction or warning. Four days earlier, Obsidian Security published three chained CVEs against LiteLLM: CVE-2026-47101 (authorization bypass), CVE-2026-47102 (privilege escalation to proxy admin), and CVE-2026-40217 (sandbox escape via exec()). Combined CVSS 9.9.

    Post summary

    The post announces the recent disclosure of multiple high‑severity CVEs—CVE‑2026‑42824, CVE‑2026‑47101, CVE‑2026‑47102, CVE‑2026‑40217—detailing their exploitation vectors (prompt injection, privilege escalation, sandbox escape) but provides no PoC, exploit code, patches, or evidence of active attacks.

    0000087
    306 followersView on X
  • Daily Security Review@securitydailyr
    Patch

    Obsidian finds CVSS 9.9 chain in LiteLLM AI gateway (CVE-2026-47101, -40217, -42271) — low-privilege user escalates to root and steals all managed AI provider API keys. Fix: v1.83.14. https://dailysecurityreview.com/cyber-security/obsidian-finds-cvss-9-9-attack-chain-in-litellm-ai-gateway/ #CyberSecurity #CloudSecurity https://t.co/GiwBuhRyBb

    Post summary

    Obsidian disclosed a high‑CVSS vulnerability chain in LiteLLM that allows a low‑privilege user to elevate to root and steal AI provider API keys, and the vendor has released patch v1.83.14.

    0000038
    119 followersView on X
  • CloudSecurityAlliance@cloudsa
    Patch

    CISO Daily Briefing: LiteLLM CVE-2026-47101 (CVSS 9.9) three-CVE chain: low-priv to RCE, 100+ AI provider keys exposed — patch to v1.83.14; M365 Copilot CVE-2026-42824 exfiltrates email, OneDrive, and MFA codes from a single legitimate Microsoft click, server-side mitigated; OMB M-26-14 mandates continuous AI monitoring, ending point-in-time audits; U.S. suspended Anthropic Fable 5/Mythos 5 for foreign nationals — AI BCP gaps are now operational risk. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260616/

    Post summary

    The briefing highlights CVE-2026-47101 and CVE-2026-42824, details their technical impact, and notes that a patch is available for LiteLLM while server-side mitigations are in place for M365 Copilot.

    00000188
    18.7K followersView on X
  • SecureChap@SecureChap
    Disclosure

    LiteLLM's virtual-key endpoint accepts an allowed_routes array from any internal_user. CVE-2026-47101 stores ["/*"] without role validation, granting the key access to every path. CVE-2026-47102 uses the key to call /user/update and set user_role to "proxy_admin" on the same record. CVE-2026-40217 then runs arbitrary Python through the Custom Code Guardrail test page. The exec() environment restores __builtins__ despite the explicit omission, exposing open and os.system. The full chain reaches the master key, provider credentials, and all traffic. Fixed in v1.83.14-stable. A privilege boundary enforced only by the value of one field is not a boundary.

    Post summary

    The notice outlines the full exploitation chain of several CVEs in LiteLLM, highlights how privilege can be escalated, and confirms a patch is available in version 1.83.14-stable.

    0000056
    157 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    #1 BREAKING: Two critical bugs CVE-2026-47101 and CVE-2026-47102 in LiteLLM before 1.83.14 let internal users escalate to proxy_admin and gain full administrative access. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerabilities-in-litellm-dis-81c99f5f

    Post summary

    Two critical privilege‑escalation bugs, CVE-2026-47101 and CVE-2026-47102, were disclosed for LiteLLM versions before 1.83.14, enabling internal users to obtain full administrative rights.

    0000068
    279 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more