CVE-2026-47102Disclosure(litellm / litellm)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch litellm litellm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-05-22); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-05-22: 1Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 1Technical Details · 2026-08-11: 105-2206-1606-1808-1108-12
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-221
Disclosure1
2026-06-161
Patch1
2026-06-181
Disclosure1
2026-08-111
General1
2026-08-121
General1
Full discourse5 posts
  • Miggo Security@MiggoSecurity
    General

    Attackers rarely need one devastating flaw. They need a sequence of small ones, each unlocking the next. CVE-2026-47101, CVE-2026-47102, CVE-2026-40217: a low-privilege token widened, access escalated to admin, code execution reaching the host. Two layers stopped it: ▪️WAF Copilot blocked the privilege escalation at the edge. ▪️The runtime sensor identified and blocked the code execution inside the app, before a CVE existed for it. Miggo Head of Architecture, Ben Stav, walks through the full chain, with equal parts technical rigor and few quirky memes. https://www.miggo.io/post/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache

    Post summary

    The post outlines a chain of CVEs and the defensive controls that prevented exploitation, providing technical details but no evidence of active attacks, patches, or exploit code.

    0002067
    142 followersView on X
  • Davin Jackson@Djax_Alpha
    General

    Defense-in-Depth in Action: How to Stop the LiteLLM Chain (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) with Panache https://api.cyfluencer.com/s/defense-in-depth-in-action-how-to-stop-the-litellm-chain-cve-2026-47101-cve-2026-47102-cve-2026-40217-with-panache-28947/1

    Post summary

    The provided excerpt lists CVE identifiers and hints at defensive measures, but lacks concrete details, PoC, or explicit mitigation information.

    00010289
    9.1K followersView on X
  • NewsTongue@NewsTongueX
    Disclosure

    🔴 Four AI tools broke same way in two weeks: prompt injection, privilege escalation, path traversal Varonis disclosed SearchLeak (CVE-2026-42824) on June 15—a silent exfiltration chain in Microsoft 365 Copilot Enterprise Search. A crafted URL triggers Copilot to search a victim's mailbox and leak data through a Bing SSRF with no user interaction or warning. Four days earlier, Obsidian Security published three chained CVEs against LiteLLM: CVE-2026-47101 (authorization bypass), CVE-2026-47102 (privilege escalation to proxy admin), and CVE-2026-40217 (sandbox escape via exec()). Combined CVSS 9.9.

    Post summary

    The post announces new CVEs disclosed by Varonis and Obsidian Security, detailing several high‑severity weaknesses in Microsoft 365 Copilot and LiteLLM, but it provides no PoC, exploit code, patch, or evidence of active attacks.

    0000087
    306 followersView on X
  • SecureChap@SecureChap
    Patch

    LiteLLM's virtual-key endpoint accepts an allowed_routes array from any internal_user. CVE-2026-47101 stores ["/*"] without role validation, granting the key access to every path. CVE-2026-47102 uses the key to call /user/update and set user_role to "proxy_admin" on the same record. CVE-2026-40217 then runs arbitrary Python through the Custom Code Guardrail test page. The exec() environment restores __builtins__ despite the explicit omission, exposing open and os.system. The full chain reaches the master key, provider credentials, and all traffic. Fixed in v1.83.14-stable. A privilege boundary enforced only by the value of one field is not a boundary.

    Post summary

    The text outlines a CVE chain involving privileged key misuse and code execution, and confirms that the vulnerability is fixed in version v1.83.14-stable.

    0000056
    157 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    #1 BREAKING: Two critical bugs CVE-2026-47101 and CVE-2026-47102 in LiteLLM before 1.83.14 let internal users escalate to proxy_admin and gain full administrative access. https://threatcluster.io/cluster/critical-privilege-escalation-vulnerabilities-in-litellm-dis-81c99f5f

    Post summary

    The text announces two new critical CVEs in LiteLLM that enable internal users to elevate privileges to full administrative access.

    0000068
    279 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more