Junglewise Threat Intelligence

CVE-2026-35029: BerriAI LiteLLM incorrect authorization in config update endpoint

CVE-2026-35029 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Berriai LiteLLM, Red Hat Lightspeed Core, litellm (PyPI). Vendors: Berriai, Red Hat, PyPI.

Executive brief

LiteLLM is an AI gateway used to manage and proxy requests to various Large Language Model (LLM) providers. A security flaw allows any authenticated user to access administrative configuration settings that should be restricted. An attacker could exploit this to steal sensitive credentials, read private server files, or execute malicious code, potentially leading to a full takeover of the AI infrastructure.

Technical details

A broken access control vulnerability exists in the `/config/update` endpoint of LiteLLM due to a missing authorization check for the 'proxy_admin' role. An authenticated attacker with low-level privileges can send a request to this endpoint to modify proxy configurations and environment variables. This can be leveraged to register custom pass-through endpoint handlers pointing to attacker-controlled Python code for Remote Code Execution (RCE). Additionally, attackers can exfiltrate sensitive environment variables (like DATABASE_URL) or read arbitrary system files (such as /etc/passwd) by manipulating the UI_LOGO_PATH and using the /get_image endpoint. The vulnerability is fixed in version 1.83.0.

Affected products

  • BerriAI litellm < 1.83.0
  • Red Hat Red Hat Ansible Automation Platform 2.6 affected
  • Red Hat Red Hat OpenShift AI 2.25 affected
  • Red Hat Red Hat OpenShift AI 3.3 affected
  • Red Hat Lightspeed Core affected

Timeline

  • 2026-02-24: other: Vulnerability discovered by SEC Consult
  • 2026-04-01: patched: Security patch released in nightly build
  • 2026-04-03: advisory: GitHub security advisory published
  • 2026-04-06: disclosed: NVD publication date
  • 2026-04-21: other: Coordinated release of SEC Consult advisory

References

Related threats