LiteLLM - Arbitrary File Read
CVE-2026-35029
Verified
Description
LiteLLM < 1.83.0 contains a broken access control vulnerability caused by lack of admin role enforcement on /config/update endpoint, letting authenticated users modify configurations, execute code, read files, and take over accounts.
Severity
High
CVSS Score
8.8
Exploit Probability
4%
Affected Product
litellm
Published Date
April 22, 2026
Template Author
theamanrawat
CVE-2026-35029.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-35029
CWE ID:
cwe-863
Remediation Steps
Update to version 1.83.0 or later.