Junglewise Threat Intelligence

CVE-2026-47101: BerriAI LiteLLM privilege escalation in API key generation

CVE-2026-47101 · Severity: high · CVSS 8.8 · Published 2026-05-21

Technologies: Berriai LiteLLM, litellm (PyPI). Vendors: Berriai, PyPI.

Executive brief

LiteLLM is a tool used to manage and proxy requests to various AI models. A security flaw allows standard users to create new API keys that have administrative permissions they should not possess. This could allow a regular user to take full control of the proxy settings, access sensitive data, or disrupt AI services.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in LiteLLM's key management endpoints. When an authenticated 'internal_user' generates a new API key, the 'allowed_routes' field is stored without verifying that the requested routes are within the scope of the creator's own permissions. Consequently, a low-privileged user can generate a key with access to administrative routes. By using this newly created key, the attacker can bypass role-based access controls (RBAC) and achieve full privilege escalation to 'proxy_admin'. The issue is fixed in version 1.83.14 by tightening caller-permission checks on key route fields.

Affected products

  • BerriAI LiteLLM < 1.83.14

Timeline

  • 2026-05-21: advisory: GitHub Advisory and NVD entry published
  • 2026-05-21: patched: Version 1.83.14 released

References

Related threats