Sceawere

Vulnerability Detail

CVE-2026-108596UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenLIT Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
openlit
Product
openlit
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T19:16:58.070Z",
  "pubdate": "2026-10-10T19:16:58.070Z",
  "executiveSummary": "OpenLIT version 2.1.0 is affected by an authorization bypass vulnerability involving improper access control in its telemetry data retrieval process.\nThe vulnerability is categorized as a Broken Access Control issue, specifically arising from the insecure reliance on client-provided headers to enforce multi-tenancy isolation.\nSuccessful exploitation allows an authenticated user to perform unauthorized cross-project data access, effectively bypassing tenant-level segmentation.\nAn attacker with valid authentication credentials for the platform can exfiltrate sensitive telemetry data, including LLM prompts, completions, and internal trace metadata, by manipulating specific HTTP request headers.\nThe risk is significant as it facilitates unauthorized access to proprietary machine learning interaction data, potentially exposing sensitive information or intellectual property processed by LLMs within the affected projects.\nThe vulnerability requires an authenticated attacker to possess knowledge of specific target identifiers, including the victim project ID and the database configuration ID, to successfully execute the bypass.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the trace read API, which fails to cryptographically verify or server-side validate the 'x-openlit-project-id' header against the authenticated user's session context.\nIn a secure multi-tenant architecture, authorization must be tied to the session state or a cryptographically signed token rather than relying on mutable headers provided by the client. OpenLIT 2.1.0 processes the 'x-openlit-project-id' header as a trusted input to scope database queries.\nThe attack flow begins with the adversary authenticating to the OpenLIT platform. Once a session is established, the adversary crafts a request to the trace read API. By manipulating the 'x-openlit-project-id' header, the attacker forces the backend application logic to query telemetry records associated with a project ID other than the one belonging to the attacker.\nTo achieve full exploitation, the attacker must also possess the target's database configuration ID. This suggests that the application's underlying database query construction mechanism uses the provided headers directly within the 'WHERE' clause of SQL or NoSQL queries without validating whether the authenticated user has authorization permissions for the specified 'x-openlit-project-id'.\nBecause the server trusts the user-supplied header, the application retrieves telemetry data—which contains raw prompts, completions, and trace telemetry—belonging to the victim project and returns it in the API response. This allows the attacker to systematically enumerate and extract telemetry data across different projects hosted on the same instance.\nThe vulnerability exposes the full stack of telemetry data captured by OpenLIT. Given that OpenLIT is designed to observe LLM operations, the impact is critical: it exposes the specific prompts sent to LLMs and the corresponding completions. This can lead to the exposure of confidential business information, PII, or internal system instructions that were intended to remain private within the scope of the victim's project environment.\nThe exploitation is purely logical and does not require complex memory corruption techniques, making it highly reproducible given the necessary identifiers."
}
CVE-2026-108596: OpenLIT Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere