216.73.217.22

CVE-2026-47101

· Published 21/05/2026 21:16 · Modified 21/05/2026 21:16

Labels: CVE-2026-47101 2026-05-21CVE-2026-47101CWE-863[email protected]

Essential information

Published
21/05/2026 21:16
Modified
21/05/2026 21:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
lite / litellm cpe:2.3:a:lite:litellm:*:*:*:*:*:*:*:*

References