Multiple security vulnerabilities affecting litellm versions < 1.84.0. The overall risk/impact is high due to privilege escalation and arbitrary file write capabilities.
CVE-2026-47101 (CVSS 8.8 — Severity): An authenticated internal_user can create API keys with access to routes that their role does not permit, enabling full privilege escalation from internal_user to proxy_admin.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting litellm versions < 1.84.0. The overall risk/impact is high due to privilege escalation and arbitrary file write capabilities.
CVE-2026-47101 (CVSS 8.8 — Severity): An authenticated internal_user can create API keys with access to routes that their role does not permit, enabling full privilege escalation from internal_user to proxy_admin.[emaillocker id="1283"]
CVE-2026-47102 (CVSS 8.7 — Severity): A user can modify their own user_role, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history.
CVE-2026-59820 (CVSS 6.1 — Severity): An authenticated user with access to LiteLLM LLM API routes can upload a crafted skill archive containing path traversal entries, allowing arbitrary file write and potentially leading to code execution depending on deployment configuration and writable paths.
CVE-2026-59819: A vulnerability in LiteLLM allows an attacker to exploit the issue by uploading a malicious ZIP archive via the Skills feature.
CVE-2026-59822: An authenticated user can bypass access controls in LiteLLM by exploiting a vulnerability affecting litellm versions < 1.84.0 that allows them to create API keys with access to routes they do not have permission for.
CVE-2026-59821: A user can modify their own user role, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. These vulnerabilities collectively present a high risk of privilege escalation and arbitrary file write capabilities. Administrators should review exposure and apply necessary security patches. These vulnerabilities collectively present a high risk of privilege escalation and arbitrary file write capabilities.
These vulnerabilities collectively present a high risk of privilege escalation and arbitrary file write capabilities.
We recommend you to update LiteLLM to version 1.84.0.
The following reports contain further technical details:
[/emaillocker]