HighVulnerability
CVE-2026-93355: LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-93355
- Published
- Record updated
Summary
LiteLLM contains a weak authentication flaw in its JWT authentication flow. An attacker holding a valid JWT from the configured identity provider can fall back to an email-based lookup without verifying the email_verified claim, authenticating as any existing user. The attacker can then inherit that user's role, including proxy_admin privileges, and overwrite the victim's stored identity binding to keep persistent access to administrative endpoints that expose API keys and user management.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumRequest, Aggregate, Bypass: How Attackers Can Evade LLM Safety ClassifiersSimilar attack · CrowdStrike Blog
- InfoWhy AI agents are like the dog that pushed kids into the SeineSimilar attack · CSO Online