CVE-2026-47102 Details
Description
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.
A privilege escalation vulnerability has been identified in LiteLLM versions prior to 1.83.10. The issue allows users with the 'internal_user' role to modify their user role to 'proxy_admin' through the '/user/update' endpoint. This exploitation is possible because the endpoint, while restricting users to update only their own accounts, fails to limit which fields can be changed. Users who successfully exploit this vulnerability gain full administrative access to LiteLLM, including control over all users, teams, keys, models, and prompt history.
Users can update to LiteLLM version 1.83.10 or later, where this vulnerability has been addressed. Instructions for verifying the authenticity of the LiteLLM Docker image are available in the release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| litellm litellm | < 1.83.10 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 2, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 11, 2026 | CVE Modified | [email protected] |
| May 22, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | New CVE Received | [email protected] |