CVE-2026-93355: LiteLLM Weak JWT Authentication via Email-Based User Lookup

Published Sep 28, 2026
·
Updated

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the emailverified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxyadmin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.

Affected Software

1 affected component
BerriAI LiteLLM

Event History

Sep 28, 2026
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Is a JWT from an arbitrary identity provider sufficient to exploit this issue?

No. The attacker needs a valid JWT issued by the identity provider configured for the LiteLLM deployment.

2

Does exploitation require user interaction or an existing administrative account?

No user interaction is required. The CVSS vector indicates low privileges are required, and a matching existing user account can be targeted to inherit that user's role, including proxy_admin.

3

What makes the unauthorized access persistent?

Successful exploitation can permanently overwrite the victim's stored identity binding. This can allow the attacker to retain access as that user after the initial impersonation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203