GITHUBEXPLOIT 8.8 HIGH

Exploit for CVE-2026-47101_B89C55B6-BB97-51C5-8FE2-2043E73BE1A8

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

CVE-2026-47101 — LiteLLM Privilege Escalation via /key/generate + /user/update LiteLLM v1.82.6(v1.83.14 之前版本)的 /key/generate 端点允许低权限的 internaluser 请求带通配符路由 "/" 的 API key,随后通过 /user/update 端点将自身角色提升为 proxyadmin,实现未授权的权限提升。 | Field | Value |...
Visit Original Source

Basic Information

ID B89C55B6-BB97-51C5-8FE2-2043E73BE1A8
Published May 25, 2026 at 09:10
Modified May 25, 2026 at 09:12

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.