Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover

Attackers are actively exploiting a critical authorization flaw in LiteLLM’s administrative API. This vulnerability allows low-privileged, read-only users to modify proxy configurations, expose sensitive secrets, and potentially gain full administrator control over affected servers. Researchers at Zenity Labs tracked approximately 3,900 requests targeting LiteLLM’s administration endpoints from February to June 2026, originating from 73 different […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: