← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 2, 2026 · 07:57via CyberPress

Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover

Brief

A broken authorization check in LiteLLM’s administrative API is being actively targeted, allowing attackers with even read-only access to alter gateway settings, expose secrets, and seize administrator control.

Zenity observed exploitation attempts against CVE-2026-35029, a broken-access-control vulnerability affecting LiteLLM’s /config/update endpoint.

The flaw, disclosed on April 6, 2026 and fixed in LiteLLM version 1.

  • 0, enables accounts assigned the supposedly limited proxy_admin_viewer role to modify settings reserved for full administrators.

Hackers Exploit LiteLLM Admin API Flaw

That poses a severe risk to LiteLLM deployments, which commonly sit between applications and AI providers and handle model-provider API keys, user data, spending records, databases, and administrator credentials.

Read more on CyberPress