No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Berriai
Berriai litellm |
|
| Vendors & Products |
Berriai
Berriai litellm |
Mon, 28 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management. | |
| Title | LiteLLM Weak JWT Authentication via Email-Based User Lookup | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T19:26:01.155Z
Reserved: 2026-09-17T18:41:40.758Z
Link: CVE-2026-93355
No data.
Status : Received
Published: 2026-09-28T20:17:11.547
Modified: 2026-09-28T20:17:11.547
Link: CVE-2026-93355
OpenCVE Enrichment
Updated: 2026-09-28T23:15:07Z