CVE-2026-35029
Impact
The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:
- Modify proxy configuration and environment variables
- Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution
- Read arbitrary server files by setting UILOGOPATH and fetching via /get_image
- Take over other priveleged accounts by overwriting UIUSERNAME and UIPASSWORD environment variables
Patches
Fixed in v1.83.0. The endpoint now requires proxy_admin role.
Workarounds
Restrict API key distribution. There is no configuration-level workaround.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/BerriAI/litellm/security/advisories/GHSA-53mr-6c8q-9789, https://nvd.nist.gov/vuln/detail/CVE-2026-35029, https://github.com/BerriAI/litellm, http://seclists.org/fulldisclosure/2026/Apr/17
