Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM versions before 1.83.0 and allows authenticated users to access the sensitive /config/update endpoint without the required administrator role. LiteLLM acts as an AI gateway between […]

This article has been indexed from Cyber Security News

Read the original article: