---
schema: 1
kind: research
title: "Obsidian Security: a three-CVE chain turns any LiteLLM user into root on the AI gateway"
headline: "Obsidian Security: a three-CVE chain turns any LiteLLM user into root on the AI gateway"
summary: "Obsidian Security published a privilege-escalation-to-RCE chain in LiteLLM (BerriAI), the widely self-hosted AI gateway that proxies 100+ LLM providers behind one OpenAI-compatible API (Obsidian Security, 2026-06-15; The Hacker News, 2026-06-15)."
discovered_at: "2026-06-16T05:09:00Z"
event_date: 2026-06-15
run_id: 2026-06-16-38d638e1
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - priv-esc
  - ai-abuse
  - poc-public
  - patch-available
regions:
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-47101
    cvss: "8.8"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - poc-public
      - patch-available
  - id: CVE-2026-47102
    cvss: "8.8"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - poc-public
      - patch-available
  - id: CVE-2026-40217
    cvss: "8.8"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce"
    publisher: Obsidian Security
    role: primary
  - url: "https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html"
    publisher: The Hacker News
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Pin LiteLLM to version ≥ 1.83.14 and keep admin endpoints off the internet (CVE-2026-47101/-47102/-40217)** — rotate all provider API keys if any pre-1.83.14 instance was reachable by untrusted users; move keys into a secrets manager."
migrated_from: briefs/2026-06-16.md
---

Obsidian Security published a privilege-escalation-to-RCE chain in **LiteLLM** (BerriAI), the widely self-hosted AI gateway that proxies 100+ LLM providers behind one OpenAI-compatible API ([Obsidian Security, 2026-06-15](https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce); [The Hacker News, 2026-06-15](https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html)). The chain: **CVE-2026-47101** (authorization bypass) — the key-generation endpoint accepts a caller-supplied `allowed_routes` without checking the caller's role, so an `internal_user` can mint a key reaching admin routes; **CVE-2026-47102** (privilege escalation) — `/user/update` lacks field-level authorization, letting any authenticated user set their own `user_role` to `proxy_admin`; **CVE-2026-40217** (RCE) — the Custom Code Guardrails feature runs attacker-supplied Python via `exec()` with `__builtins__` available, giving arbitrary code execution. VulnCheck scores CVE-2026-47102 at CVSS 8.8 (3.1), and Obsidian rates the chained impact CVSS 9.9; chained, a default low-privilege account reaches the master key, the salt key decrypting stored secrets, the database URL and every configured provider API key — and can rewrite responses delivered to downstream AI agents ("man-in-the-gateway"). Fixed in **v1.83.14-stable**, but Obsidian reports broad under-deployment of the fix. Mapped to `T1078`, `T1548` and `T1059.006`.

**Why it matters to us:** Swiss/EU public-sector and research bodies increasingly centralise AI workflows on a gateway proxy; a compromised LiteLLM is both a credential-theft and an agent-manipulation vector. Pin LiteLLM to ≥1.83.14, keep admin endpoints off the internet, store provider keys in a secrets manager, and rotate all provider keys if any pre-1.83.14 instance was reachable by untrusted users.
