Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-47102

3 месяца назад

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-47102

3 месяца назад

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-wpfp-gwwc-vwq6

3 месяца назад

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-08669

6 месяцев назад

Уязвимость функции user_role прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-47102

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS3: 8.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-47102

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-wpfp-gwwc-vwq6

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

CVSS3: 8.8
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-08669

Уязвимость функции user_role прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером

CVSS3: 8.8
1%
Низкий
6 месяцев назад

Уязвимостей на страницу