Skip to main content

Broken Access Control in Config Endpoint in LiteLLM

An incomplete authorization check in LiteLLM allowed low privileged attackers to access sensitive data on the host system.
CVE-2026-35029

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 17

  • Magazine

Digital security magazine 18th Edition