Incorrect Authorization Affecting litellm-1.83-bin package, versions <1.83.10-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.06% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-MINIMOSLATEST-LITELLM183BIN-17093269
  • published30 May 2026
  • disclosed21 May 2026

Introduced: 21 May 2026

NewCVE-2026-47102  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade Minimos:latest litellm-1.83-bin to version 1.83.10-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream litellm-1.83-bin package and not the litellm-1.83-bin package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt history. Users with the org_admin role have legitimate access to this endpoint and can exploit this vulnerability without chaining any additional flaw.

CVSS Base Scores

version 3.1