Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-47102

Опубликовано: 21 мая 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
Версия до 1.83.10 (исключая)

EPSS

Процентиль: 48%
0.00654
Низкий

8.8 High

CVSS3

Дефекты

CWE-863
CWE-915

Связанные уязвимости

CVSS3: 8.8
redhat
3 месяца назад

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS3: 8.8
github
3 месяца назад

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

CVSS3: 8.8
fstec
6 месяцев назад

Уязвимость функции user_role прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером

EPSS

Процентиль: 48%
0.00654
Низкий

8.8 High

CVSS3

Дефекты

CWE-863
CWE-915