CVE-2026-93355 is a weak-authentication vulnerability in LiteLLM JWT identity resolution affecting versions through 1.102.1. When direct lookup of a JWT subject does not identify a user, LiteLLM can fall back to matching the token's email claim against an existing account without validating the email_verified claim. A holder of a valid JWT from the deployment's trusted identity provider can therefore assert an unverified email address belonging to another LiteLLM user and authenticate as that user. The fallback flow can also replace the victim account's stored SSO identity binding with the attacker's JWT subject, making the unauthorized access persistent.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity authentication-bypass and account-takeover vulnerability in LiteLLM JWT identity resolution. On a direct user/SSO identity lookup miss, LiteLLM matches an existing account using an unverified JWT email claim, authenticates as that account, and asynchronously overwrites its sso_user_id with the attacker's token subject, creating persistent access. This can enable takeover of proxy_admin accounts and access to LiteLLM-managed upstream LLM API keys and administrative controls.
A high-severity weak-authentication flaw in LiteLLM's JWT authentication fallback path. Failure to validate the email_verified JWT claim allows a holder of a valid token from the trusted identity provider to impersonate an existing user by matching their email address, potentially gaining proxy_admin privileges and persistently rebinding the victim's identity.
A weak JWT authentication flaw in LiteLLM in which an attacker can use a valid identity-provider JWT containing an unverified email address matching an existing victim account to impersonate that user. The fallback email lookup grants the victim's role, potentially including proxy_admin, and overwrites the stored identity binding, enabling persistent unauthorized access to administrative API-key and user-management endpoints.
A weak JWT authentication flaw in LiteLLM. An attacker with a valid identity-provider JWT containing an unverified email address matching an existing victim account can impersonate that user, inherit their role—including proxy_admin—and overwrite the victim's identity binding for persistent unauthorized administrative access, including API-key and user-management endpoints.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.