Critical Privilege Escalation Vulnerabilities in LiteLLM Disclosed
Article Content
- •CVE-2026-47101 allows privilege escalation for internal users creating unauthorized API keys.
- •CVE-2026-47102 enables users to change their roles to proxy_admin, gaining full access.
- •Both vulnerabilities were disclosed on 2026-05-21 and affect LiteLLM versions prior to 1.83.14.
Two critical vulnerabilities (CVE-2026-47101 and CVE-2026-47102) have been identified in LiteLLM versions prior to 1.83.14. CVE-2026-47101 allows authenticated internal users to create API keys with unauthorized access, enabling privilege escalation to proxy_admin. CVE-2026-47102 permits users to modify their own user_role, potentially granting full administrative access. Both vulnerabilities were published on 2026-05-21 and affect users with org_admin and internal_user roles. Exploitation can lead to unauthorized access to sensitive data and administrative functions. Users are urged to update to the latest version to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-47101 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…