Skip to content
LiteLLMGHSA-wpfp-gwwc-vwq6

LiteLLM allows a user to modify their own user_role via the /user/update endpoint

High8.8CVE-2026-47102 · Published May 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
< 1.83.101.83.10
Details and references

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2026-47102, PYSEC-2026-2600

More LiteLLM advisories

All LiteLLM
DateAdvisory
May 21LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit
CVE-2026-47101High8.8fixed in 1.83.14
May 11LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-40217High8.8fixed in 1.83.10
Apr 25LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42271High8.8fixed in 1.83.7
Apr 24LiteLLM has SQL Injection in Proxy API key verification
CVE-2026-42208Critical9.8fixed in 1.83.7
Apr 24LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-42203Highfixed in 1.83.7
Jun 16LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-49468Critical9.8fixed in 1.84.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.