REDHAT-BUG-2480634: High severity LiteLLM vulnerability

Published May 21, 2026
·
Updated

LiteLLM prior to 1.83.10 allows a user to modify their own userrole via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxyadmin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the orgadmin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

Affected Software

1 affected component
LiteLLM<1.83.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LiteLLM to a version that resolves this vulnerability.

    Fixed in 1.83.10
  2. Configuration

    Ensure the /user/update endpoint does not allow users to modify the user_role field (only allow permitted self-account fields).

    LiteLLM /user/update endpoint user_role modification = disallow changes to user_role
  3. Operational

    Review for any accounts whose user_role was modified to proxy_admin and revoke/regenerate any affected access as needed after patching.

Event History

May 21, 2026
Data Sourced
via Red Hat·09:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which users can exploit this issue without needing another vulnerability?

Users with the org_admin role have legitimate access to the /user/update endpoint and can exploit the issue directly. They can change their own user_role to proxy_admin.

2

What access does an attacker gain after changing their role?

The attacker gains full LiteLLM administrative access as proxy_admin, including access to users, teams, keys, models, and prompt history.

3

What versions are affected?

LiteLLM versions prior to 1.83.10 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203