S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 22, 2026

CVE-2026-35029 Scanner

CVE-2026-35029 Scanner - Arbitrary File Read vulnerability in LiteLLM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-35029
8.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
litellmby BerriAI
< 1.83.0
Red Hat Ansible Automation Platform 2.6by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat OpenShift AI 2.25by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat OpenShift AI 3.3by Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Aug 22, 2026View on NVD →
Detail

LiteLLM is a widely used software in the development and deployment of AI and machine learning models. It is utilized by companies that require scalable machine learning systems and is often used on cloud platforms due to its efficiency in handling large datasets. Developers and data scientists use LiteLLM to streamline model training processes and optimize machine learning workflows. The software supports various integration methods, making it versatile in different environments. Its user-friendly interface and robust API support contribute to its popularity among professionals in AI research and development. LiteLLM continues to evolve, supporting the latest AI technologies and methodologies.

The vulnerability detected in LiteLLM versions below 1.83.0 allows arbitrary file reading due to broken access control on the /config/update endpoint. This security flaw arises from inadequate enforcement of admin role permissions, which lets authenticated users exploit the endpoint, read sensitive files, and potentially modify configurations. Such vulnerabilities are critical as they may lead to unauthorized access to confidential information, including system passwords and personal data. Addressing this vulnerability requires understanding its impact across various system components it might be integrated with. Weak access controls like this are common targets for attackers seeking to escalate privileges or access sensitive data.

Technical analysis reveals that the /config/update endpoint is vulnerable, lacking proper admin role enforcement. Authenticated users can exploit this by setting the FILE_TO_READ parameter to target specific files and extract them remotely using crafted requests. The payloads crafted in the requests enable attackers to interfere with environment variables, which can manipulate how the software interacts with system files. Attackers can encode their exfiltration targets using base64, masking their actions and making detection harder unless proactive monitoring is employed. This vulnerability emphasizes the importance of stringent role-based access controls in application security.

If exploited, this vulnerability allows malicious users to gain unauthorized access to protected file contents, leading to potential information disclosure. This could further escalate into full system compromise if sensitive configuration files or credentials are extracted and misused. The ability to read arbitrary files could be leveraged to uncover system architecture details, personal user data, or other security measures in place. Such information could facilitate more severe exploits, compounding the damaging effects of the initial breach. Companies using vulnerable LiteLLM versions may face data breaches, legal issues, and damage to their reputation.

REFERENCES

Solution Advice
  • Update LiteLLM to version 1.83.0 or later to patch the broken access control vulnerability.
  • Implement strict role-based access controls to ensure that sensitive endpoints are accessible only to authorized admin users.
  • Monitor access logs for unusual activities that may indicate exploitation attempts on the /config/update endpoint.
  • Conduct regular security audits and penetration testing to identify and remediate similar vulnerabilities.
  • Consider using a web application firewall to identify and block malicious traffic targeting vulnerable endpoints.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.