Junglewise Threat Intelligence

CVE-2026-47102: BerriAI LiteLLM privilege escalation in user update endpoint

CVE-2026-47102 · Severity: high · CVSS 8.8 · Published 2026-05-21

Technologies: Berriai LiteLLM, litellm (PyPI). Vendors: Berriai, PyPI.

Executive brief

LiteLLM, a popular tool for managing access to various AI models, contains a flaw that allows standard users to upgrade their own account permissions. By sending a specifically crafted request to the user update service, any user can grant themselves full administrative control. This allows an attacker to access sensitive data including prompt history, API keys, and the accounts of all other users and teams.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in LiteLLM's /user/update and /user/bulk_update endpoints. While the application correctly verifies that a user is only modifying their own record, it fails to implement field-level access control on the 'user_role' attribute. A remote authenticated attacker with low privileges (such as org_admin or a standard user) can submit a request to change their role to 'proxy_admin'. Once escalated, the attacker gains full control over the LiteLLM proxy, including the ability to view prompt history, manage API keys, and modify other users. This issue is resolved in version 1.83.10.

Affected products

  • BerriAI LiteLLM < 1.83.10

Timeline

  • 2026-04-12: patched: Fix merged into main repository
  • 2026-05-21: disclosed: Initial NVD and GitHub Advisory publication
  • 2026-06-23: advisory: Advisory updated with reviewed details

References

Related threats