CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

LiteLLM Authorization Bypass via Allowed Routes

June 25, 2026

CVE-2026-47101 is an authorization bypass vulnerability in LiteLLM where the allowed_routes field is not validated against user roles, allowing low-privilege users to generate virtual API keys with wildcard routes that grant admin-level access.