CVE detail
CVE-2026-35029
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
9 source links · newest first
to conduct attacks against third-parties and power their own offensive operations . These efforts involve the abuse of CVE-2024-6587 , CVE-2026-40217 , and CVE-2026-35029. "Self-hosted model servers and agent frameworks keep getting deployed while being misconfigured and unauthenticated, on predictable ports, willing to serve any client," Zenity said
newsthehackernews.comJul 24, 2026, 11:53 AM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35029.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comApr 6, 2026, 5:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2455474bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 6, 2026, 5:17 PM - https://access.redhat.com/security/cve/CVE-2026-35029access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 6, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:30056access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 6, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:28960access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 6, 2026, 5:17 PM - https://access.redhat.com/errata/RHSA-2026:13545access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comApr 6, 2026, 5:17 PM - http://seclists.org/fulldisclosure/2026/Apr/17seclists.org
No excerpt available.
Exploitseclists.orgApr 6, 2026, 5:17 PM No excerpt available.
Exploitgithub.comApr 6, 2026, 5:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33217CVSS 7.1 · High
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these AC…
- CVE-2026-12797CVSS 2.1 · Low
A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the…
- CVE-2026-47102CVSS 8.7 · High
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account…
- CVE-2026-47101CVSS 8.7 · High
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes…
- CVE-2026-58159CVSS 7.0 · High
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0…
- CVE-2025-10656CVSS 9.8 · Critical
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi…