Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93355— LiteLLM Weak JWT Authentication via Email-Based User Lookup

Quick assessment

Affected
BerriAI litellm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LiteLLM 存在一个弱的认证漏洞,允许持有由配置的身份提供商签发的有效 JWT(JSON Web Token)的攻击者,通过在 JWT 认证流程中利用基于电子邮件的回退查找机制(该机制未验证 声明),以任意现有用户的身份进行认证。攻击者可以提交一个包含未验证电子邮件地址的令牌,该地址与目标用户的账户电子邮件相匹配,从而继承该目标用户的角色权限,包括 管理员权限。此攻击还会永久覆盖目标用户存储的身份绑定信息,使攻击者能够持续未授权地访问暴露 API 密钥和用户管理功能的后台管理接口。

CVSS 8.1 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
BerriAI litellm ≤ 1.102.1 affected
≤ f4308bc124eebc783dfc51790ce8db27ed21ae00 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93355

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LiteLLM Weak JWT Authentication via Email-Based User Lookup
Source: CVE Program / CVE List V5
Vulnerability Description
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1390
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
BerriAI litellm 0 ~ 1.102.1 -

II. Public POCs for CVE-2026-93355

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93355

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93355 (1)

Security Blog Posts for CVE-2026-93355 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93355

No comments yet


Leave a comment