Description
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.
Published: 2026-09-28
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Weak JWT Authentication
Action: Immediate Patch
AI Analysis

Impact

LiteLLM's authentication flow allows an attacker who possesses a valid JSON Web Token issued by the configured identity provider to log in as any existing user. The vulnerability stems from an email-based fallback lookup that does not validate the email_verified claim. Attackers can craft a token containing an unverified email address that matches a victim's account, thereby inheriting the victim's role—including proxy_admin privileges. Once authenticated, the attacker can permanently overwrite the victim’s stored identity binding, ensuring continued unauthorized access to administrative endpoints such as API key management and user configuration.

Affected Systems

BerriAI:LiteLLm is the affected vendor/product. Specific affected versions are not supplied, but any deployment of LiteLLM that uses the default JWT authentication configuration is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.6 signifies a high severity, with a large impact if exploited. EPSS is not available, so the current probability of exploitation cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to already possess a valid JWT, but an attacker can guess or discover a victim’s email address through publicly available information or enumeration. Once the email is mirrored in the forged token, the authentication bypass occurs and the attacker can credibly impersonate the victim and modify stored identities, giving them permanent administrative access.

Generated by OpenCVE AI on September 28, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest LiteLLM release that contains the authentication fix (verify the vendor’s patch notes for a fix to email verification handling).
  • Configure the JWT authentication flow to enforce the email_verified claim before granting access and disable the email‑based fallback lookup that allows impersonation.
  • Audit the system for any overwritten identity bindings and revoke any compromised credentials; rotate all administrative API keys and password policies afterwards.

Generated by OpenCVE AI on September 28, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.
Title LiteLLM Weak JWT Authentication via Email-Based User Lookup
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T19:26:01.155Z

Reserved: 2026-09-17T18:41:40.758Z

Link: CVE-2026-93355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T20:17:11.547

Modified: 2026-09-28T20:17:11.547

Link: CVE-2026-93355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T20:30:06Z

Weaknesses