CVE-2026-35029: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already a...
Added to the CISA Known Exploited Vulnerabilities catalog on 06 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environm...
Required action: Review and patch if applicable to your AI infrastructure.