
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
A broken authorization check in LiteLLM’s administrative API is being actively targeted, allowing attackers with even read-only access to alter gateway settings, expose secrets, and seize administrator control. Zenity observed exploitation attempts against CVE-2026-35029, a broken-access-control vulnerability affecting LiteLLM’s /config/update endpoint. The flaw, disclosed on April 6, 2026 and fixed in LiteLLM version 1.83.0, enables […]
The post Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover appeared first on Cyber Security News.