CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

September 10, 2026

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key Swati KhandelwalSep 10, 2026Cloud Security / Artificial Intelligence Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every model provider's API key stored on the server. In Wiz's tests, it also reached the cloud IAM credentials of the machine the gateway runs on. Changing the key needs no upgrade, and it closes every path in Wiz's…

CVEs: CVE-2026-59821, CVE-2026-40217, CVE-2026-59822, CVE-2026-42271, CVE-2026-48710