Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
ID: 7599e247-2f5b-5694-a6ea-78e5ad1424db
STIX ID: report--7599e247-2f5b-5694-a6ea-78e5ad1424db
Feed Name: GBHackers
Researchers at Zenity Labs observed active exploitation of CVE-2026-35029 — a missing authorization check in LiteLLM's admin API — allowing read-only accounts to change configuration (e.g., UI_LOGO_PATH) to read sensitive files, extract environment-held secrets, and potentially gain full administrative control; ~3,900 requests from 73 IPs were tracked with nearly 1,000 targeting /config/update. The report documents observed file-read payloads, key-guessing and admin-creation attempts, provides reproduction details, and advises upgrading to LiteLLM 1.83.0, rotating secrets, restricting control-plane access, and monitoring specific endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
