8.8
CVE-2026-47102
- EPSS 0.65%
- Veröffentlicht 21.05.2026 20:34:37
- Zuletzt bearbeitet 23.07.2026 16:10:00
- CVE-Watchlists
- Unerledigt
LiteLLM < 1.83.10 Privilege Escalation via User Update
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.475 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f
https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9
https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-user-update
https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce
https://bugzilla.redhat.com/show_bug.cgi?id=2480634
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47102.json
https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable
https://github.com/BerriAI/litellm/commit/128d32d2494b759c5d15da3452452af4c6a34c01
https://github.com/BerriAI/litellm/commit/e6f18ce75b111c9b93dc15c72894cbdeb53177ce
https://github.com/BerriAI/litellm/pull/25541
https://access.redhat.com/security/cve/CVE-2026-47102