CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

LiteLLM Privilege Escalation via User Update Endpoint

June 25, 2026

CVE-2026-47102 is a privilege escalation vulnerability in LiteLLM's /user/update endpoint, which does not restrict field updates, allowing users to self-promote to proxy_admin by setting user_role to proxy_admin.