Improper access control in LiteLLM - CVE-2026-35029
Published: April 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code, disclose sensitive information, and escalate privileges.
The vulnerability exists due to improper access control in the /config/update endpoint when handling configuration update requests. A remote user can modify proxy configuration and environment variables to execute arbitrary code, disclose sensitive information, and escalate privileges.
The issue can be exploited by a user who is already authenticated into the platform.
Affected software
Python for Scientific Computing
How to mitigate CVE-2026-35029
Python for Scientific Computing - update to 4.3.2