๐Ÿ” CVE Alert

CVE-2026-47101

HIGH 8.8

LiteLLM < 1.83.14 Privilege Escalation via API Key Generation

CVSS Score
8.8
EPSS Score
0.1%
EPSS Percentile
16th

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.

CWE CWE-863
Vendor berriai
Product litellm
Published May 21, 2026
Last Updated May 23, 2026
Stay Ahead of the Next One

Get instant alerts for berriai litellm

Be the first to know when new high vulnerabilities affecting berriai litellm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

BerriAI / litellm
0 < 1.83.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f huntr.com: https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9 github.com: https://github.com/BerriAI/litellm/releases/tag/v1.83.14-stable github.com: https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c github.com: https://github.com/BerriAI/litellm/commit/2220f3076ac89bd2a2e3439acf57dcfbec2434c9 github.com: https://github.com/BerriAI/litellm/commit/5190bd07eb23a037745d86328096f54378f1614a vulncheck.com: https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-api-key-generation

Credits

Fenix Qiao (aka 13ph03nix) from Obsidian Security