๐Ÿ” CVE Alert

CVE-2026-47102

HIGH 8.8

LiteLLM < 1.83.10 Privilege Escalation via User Update

CVSS Score
8.8
EPSS Score
0.1%
EPSS Percentile
16th

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CWE CWE-863
Vendor berriai
Product litellm
Published May 21, 2026
Last Updated May 23, 2026
Stay Ahead of the Next One

Get instant alerts for berriai litellm

Be the first to know when new high vulnerabilities affecting berriai litellm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

BerriAI / litellm
0 < 1.83.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f huntr.com: https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9 github.com: https://github.com/BerriAI/litellm/releases/tag/v1.83.10-stable github.com: https://github.com/BerriAI/litellm/pull/25541 github.com: https://github.com/BerriAI/litellm/commit/e6f18ce75b111c9b93dc15c72894cbdeb53177ce github.com: https://github.com/BerriAI/litellm/commit/128d32d2494b759c5d15da3452452af4c6a34c01 vulncheck.com: https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-user-update

Credits

Fenix Qiao (aka 13ph03nix) from Obsidian Security