Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM versions before 1. 83. 0 and allows authenticated users to access the sensitive /config/update endpoint without the required administrator role. LiteLLM acts as an AI gateway between enterprise applications and model providers. It can store provider API keys, database connection details, user data, spending records, and administrative credentials. This makes exposed LiteLLM control planes a valuable target for attackers seeking cloud credentials, AI service keys, or a path into connected infrastructure. The vulnerability stems from the absence of an authorization check on the /config/update API route.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover

A broken authorization check in LiteLLM’s administrative API is being actively targeted, allowing attackers with even read-only access to alter gateway settings, expose secrets, and seize administrator control. Zenity observed exploitation attempts against CVE-2026-35029, a broken-access-control vulnerability affecting LiteLLM’s /config/update endpoint. The flaw, disclosed on April 6, 2026 and fixed in LiteLLM version 1. 83. 0, enables accounts assigned the supposedly limited proxy_admin_viewer role to modify settings reserved for full administrators. Hackers Exploit LiteLLM Admin API Flaw That poses a severe risk to LiteLLM deployments, which commonly sit between applications and AI providers and handle model-provider API keys, user data, spending records, databases, and administrator credentials.

·CyberPress
Read →

You've reached the end of current stories for this search.