CVE-2026-89032

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding a valid virtual key can submit semantically similar prompts on affected routes such as /v1/responses and /bedrock/* to retrieve cached responses containing other tenants' personally identifiable information, financial data, or source code, and can cause agentic front-ends to auto-execute attacker-supplied tool calls under victim credentials by returning cached function_call or tool_calls payloads to a different principal.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - LiteLLM Semantic Cache Tenant Isolation Bypass (CVE-2026-89032) BerriAI LiteLLM semantic cache mis-associates entries due to a metadata key mismatch, letting any authenticated user with a valid virtual key hit /v1/responses or /bedrock/* with semantically similar prompts to pull cached responses from other tenants. Impact: cross-tenant data leakage (PII/financial/source) and potential tool_calls/function_call replay causing agentic UIs to execute actions under victim creds. 👉Affected: litellm < 1.101.0-rc.1 | Upgrade to 1.101.0-rc.1

    1000048
    306 followersView on X

Explore more