CVE-2026-35029 is an incorrect authorization vulnerability in LiteLLM versions before 1.83.0. The configuration-update functionality, including the update_config handling path, failed to require the PROXY_ADMIN role. Consequently, an authenticated low-privilege user could modify administrator-only proxy configuration and environment settings. Abuse can include registering custom pass-through handlers referencing attacker-controlled Python code, changing UI configuration to expose files readable by the LiteLLM process, and replacing dashboard credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a standalone Python PoC for CVE-2026-35029, a broken access control issue in LiteLLM < 1.83.0 where authenticated non-admin users can call /config/update without the required proxy_admin role. The repo contains 11 files: documentation (README.md, docs/advisory.md, screenshots/README.md), environment orchestration (docker-compose.yml, litellm_config.yaml, requirements.txt), an attacker exfiltration service (exfil-server/Dockerfile and exfil-server/server.py), and exploit logic (exploit/exploit.py and exploit/payload.py). The main exploit flow in exploit/exploit.py uses requests to: verify target reachability, POST malicious JSON to /config/update, register pass-through endpoints, trigger those endpoints, and then fetch attacker-side logs from /logs. payload.py builds three malicious config payloads: one for environment variable exfiltration by mapping headers like X-Exfil-*-VAR to os.environ/VAR, one for file-read style abuse using LANGFUSE-related headers, and one for overwriting UI credentials. The included exfiltration server is a simple Python HTTP server that listens on port 9999, logs all inbound headers/body, exposes /health and /logs, and base64-decodes selected header values for easier inspection. docker-compose.yml creates a reproducible lab with PostgreSQL, a vulnerable LiteLLM image pinned by digest on port 4000, an optional fixed LiteLLM on port 4001, and the attacker exfiltration server on port 9999. The exploit’s primary demonstrated capability is unauthorized configuration modification leading to secret exfiltration (e.g., LITELLM_MASTER_KEY, DATABASE_URL, AWS_SECRET_ACCESS_KEY, OPENAI_API_KEY). The repository also documents additional impact including arbitrary file read, admin credential overwrite, and possible RCE through attacker-controlled pass-through handlers. Overall, this is a real operational PoC rather than a detector: it actively changes target configuration and exfiltrates data to attacker infrastructure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability published on April 3, 2026. The supplied CVSS vectors describe network-based exploitation with low attack complexity, low privileges, no user interaction, and high confidentiality, integrity, and availability impacts. The content does not identify the affected product or underlying flaw.
A LiteLLM authorization vulnerability in the pass-through configuration-update route that lacked an administrator authorization check. It could enable configuration of pass-through destinations, including an AWS metadata-service target, when access controls fail.
An authorization flaw in LiteLLM's pass-through configuration-update route that allowed configuration of pass-through destinations without an administrator check. With access-control failures, pass-through could be abused to target internal services or the AWS instance metadata service and obtain temporary IAM credentials.
An authorization vulnerability in LiteLLM's configuration-update functionality that allowed any authenticated API-key user, rather than only an administrator, to configure arbitrary pass-through proxy endpoints. This could enable access to internal services such as cloud metadata endpoints.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.