A high-severity authentication flaw, CVE-2026-93355, in LiteLLM's JWT identity-resolution flow can let an attacker impersonate an existing user by presenting a valid token from the configured identity provider with the victim's email address. When subject-based matching fails, affected versions perform a case-insensitive email fallback without verifying the email_verified claim. An attacker targeting a proxy_admin account could access administrative endpoints, user and key records, and upstream LLM-provider API keys managed by the LiteLLM proxy.
The fallback can also overwrite the victim's stored sso_user_id with the attacker's JWT subject, turning the initial impersonation into persistent access. LiteLLM versions through 1.102.1 are affected, with 1.102.2 and later fixing the issue; public reporting found no known active exploitation or CISA KEV listing. Organizations should upgrade immediately, investigate identity-binding changes, rotate exposed virtual and provider API keys, and reject JWTs that lack verified email claims until remediation is complete.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
After approximately 120 days without a reported vendor response, OX Research publicly disclosed the LiteLLM authentication-bypass issue. The attack can impersonate a matched user and persistently rebind the victim account's SSO identity to an attacker-controlled JWT subject.
LiteLLM version 1.100.1 was published and was reported to remain vulnerable to the JWT email-fallback authentication bypass.
OX Research sent LiteLLM a follow-up concerning CVE-2026-93355 and reported receiving no vendor response.
OX Research reported the JWT identity-resolution vulnerability later designated CVE-2026-93355 to LiteLLM. The issue allows an unverified email claim from a trusted identity provider to match an existing account and impersonate that user.
LiteLLM version 1.102.2 and later were identified as fixing CVE-2026-93355, which affects versions through 1.102.1. The fix addresses fallback email identity matching without validation of the JWT email_verified claim.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.