CVE-2026-35029
BerriAI litellm, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 2.25
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSW...
- CVSS
- 8.7
- EPSS
- 26.4% 97.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.07