Sceawere

Vulnerability Detail

CVE-2026-108575UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LiteLLM Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
BerriAI
Product
LiteLLM
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in BerriAI LiteLLM up to 1.94.0. This affects the function get_secret of the file secret_managers/main.py of the component Secret Resolution. The manipulation of the argument api_key leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-11T12:16:53.210Z",
  "pubdate": "2026-10-11T12:16:53.210Z",
  "executiveSummary": "A critical improper authorization vulnerability exists in the Secret Resolution component of BerriAI LiteLLM, affecting all versions up to 1.94.0.\nThe vulnerability resides within the get_secret function of secret_managers/main.py, where improper handling of the api_key argument allows for unauthorized secret access.\nThis flaw enables remote attackers to bypass existing security controls to retrieve sensitive credentials managed by the application.\nGiven that the exploit is publicly disclosed and the vendor has not responded to disclosures, the risk is elevated as threat actors can leverage this publicly available information to compromise instances.\nThe vulnerability requires no prior authentication and can be exploited over a network, making it a high-risk security issue for deployments utilizing LiteLLM secret management.",
  "technicalDetails": "The vulnerability is located in the secret resolution mechanism of BerriAI LiteLLM, specifically within the get_secret function inside secret_managers/main.py.\nThe root cause of this issue is an improper authorization check or validation flaw when the application processes the api_key argument. Instead of strictly validating that the requester has the appropriate authorization level to access or retrieve a specific secret, the function inadequately validates the input provided.\nThe attack flow begins with a remote attacker identifying an instance of LiteLLM reachable over the network. By manipulating the api_key argument in a request processed by the get_secret function, an attacker can influence the function's internal logic.\nDue to the failure to properly enforce authorization boundaries, the function improperly processes the attacker-supplied input, leading to the retrieval of sensitive API keys or secrets that should otherwise be protected or restricted to authorized users or roles only.\nThe vulnerability is exploitable remotely without requiring authentication or elevated privileges. Because the function responsible for retrieving secrets does not correctly verify the caller's identity or authorization context, an attacker can send crafted requests to exfiltrate secret data stored within the system's secret management configuration.\nThe post-exploitation impact includes the potential for unauthorized access to third-party services integrated with LiteLLM, as attackers can obtain the credentials required to impersonate the application or its users.\nThis behavior is consistent with an improper authorization vulnerability where the system fails to correctly map the user's privileges to the requested resource, allowing for unauthorized data disclosure."
}
CVE-2026-108575: LiteLLM Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere