CYBERSECURITY BRIEFING NOTE OVERVIEW: CVE-2026-35029 affects LiteLLM versions prior to 1.83.0, an AI Gateway proxy server that facilitates communication with large language model APIs. The vulnerability exists in the /config/update endpoint, which fails to enforce administrative role authorization, allowing any authenticated user to modify proxy configuration settings and environment variables without proper access controls. SEVERITY: The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and a low-privilege user account. An authenticated attacker can achieve remote code execution by registering custom pass-through handlers pointing to malicious Python code, read arbitrary files from the server through UI_LOGO_PATH manipulation, and escalate privileges by overwriting administrative credentials. The attack vector requires no user interaction and completely compromises the confidentiality, integrity, and availability of the affected system. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as CVE-2026-35029 is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains on the inactive Hot List. However, the EPSS score of 0.10 indicates heightened concern relative to the overall CVE population. Organizations running LiteLLM versions below 1.83.0 should prioritize patching, as the attack requires only valid authentication credentials and the technical barriers to exploitation are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.83.0CPE matchmatch criteria | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.