Skip to content
Threat Feed
high advisory

Weak Authentication Vulnerability in LiteLLM (CVE-2026-93355)

LiteLLM contains a critical authentication flaw where failure to validate JWT email claims allows attackers to impersonate arbitrary users and escalate to administrative privileges.

CVE search metadata

CVE search record: CVE-2026-93355. Severity: high. CVSS: 8.1. KEV: no. Product: LiteLLM. Brief: Weak Authentication Vulnerability in LiteLLM (CVE-2026-93355). Brief link: https://feed.craftedsignal.io/briefs/2026-09-litellm-auth-bypass/

LiteLLM is susceptible to a weak authentication vulnerability, identified as CVE-2026-93355. The flaw exists within the application's JWT-based authentication flow, specifically regarding the handling of identity provider (IdP) tokens. When a user presents a JWT, the application performs an email-based lookup to identify the account. Crucially, the system fails to verify the 'email_verified' claim contained within the token.

This oversight allows an attacker who possesses a valid JWT from a configured IdP to specify an unverified email address that corresponds to an existing target account. The application incorrectly maps the attacker's token to the victim's profile, granting the attacker the permissions associated with that account. In scenarios where the targeted account holds administrative roles, such as 'proxy_admin', the attacker can achieve full privilege escalation. Furthermore, the vulnerability enables the attacker to overwrite the stored identity binding for the victim, facilitating persistent unauthorized access to administrative interfaces, API key repositories, and user management functions. This impact is significant for organizations relying on LiteLLM for LLM orchestration and proxy services.

Attack Chain

  1. Attacker obtains a valid JWT from a configured IdP (e.g., via personal registration or unauthorized account creation).
  2. Attacker modifies the JWT payload (if necessary) or uses an IdP account to inject an email address matching a victim's administrative account.
  3. Attacker initiates an authentication request to the LiteLLM application passing the crafted JWT.
  4. The LiteLLM authentication service processes the incoming JWT.
  5. The service executes an email-based lookup for the account associated with the provided email string.
  6. The service fails to validate the 'email_verified' claim, allowing the mapping to succeed despite the email being unverified.
  7. LiteLLM establishes a session context for the victim user, granting the attacker administrative access (proxy_admin).
  8. Attacker modifies identity bindings to permanently associate the victim's account with the attacker's controlled token, ensuring persistence.

Impact

Successful exploitation of CVE-2026-93355 allows for full account takeover of any existing user within the LiteLLM instance. This includes accounts with administrative privileges, granting unauthorized access to sensitive API keys, proxy management, and infrastructure configurations. Given the centralized role of LiteLLM in proxying LLM interactions, this vulnerability poses a severe risk to the confidentiality and integrity of AI-driven workflows and associated data.

Recommendation

Prioritize the immediate application of security patches or updates provided by the LiteLLM vendor to address CVE-2026-93355. Ensure that the application is configured to strictly enforce the 'email_verified' claim during JWT validation processes. If patching is not immediately feasible, restrict access to the authentication interface by implementing IP-based allowlisting at the reverse proxy or firewall layer to mitigate unauthenticated or unauthorized token injection attempts.


Immediate actions

Patch LiteLLM to address CVE-2026-93355

IT Operations 24h

Mitigations

Restrict access to authentication endpoints via WAF or reverse proxy

immediate IT Operations

CVE-2026-93355