LiteLLM < 1.83.0 contains a broken access control vulnerability caused by lack of admin role enforcement on /config/update endpoint, letting authenticated users modify configurations, execute code, read files, and take over accounts.
id: CVE-2026-35029
info:
name: LiteLLM - Arbitrary File Read
author: theamanrawat
severity: h
...