Improper access control in LiteLLM - CVE-2026-35029
Published: April 7, 2026
LiteLLM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code, disclose sensitive information, and escalate privileges.
The vulnerability exists due to improper access control in the /config/update endpoint when handling configuration update requests. A remote user can modify proxy configuration and environment variables to execute arbitrary code, disclose sensitive information, and escalate privileges.
The issue can be exploited by a user who is already authenticated into the platform.