Количество 4
Количество 4
CVE-2026-47101
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.
CVE-2026-47101
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin.
GHSA-qrc4-49gv-mv9m
LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
BDU:2026-08670
Уязвимость функции internal_user прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-47101 LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-47101 LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-based access controls that would otherwise block the request, enabling full privilege escalation from internal_user to proxy_admin. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
GHSA-qrc4-49gv-mv9m LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
BDU:2026-08670 Уязвимость функции internal_user прокси-сервера LiteLLM, позволяющая нарушителю повысить свои привилегии и получить полный контроль над прокси-сервером | CVSS3: 8.8 | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу