THE page discusses a critical vulnerability (CVE-2026-35029) in the LiteLLM AI gateway, which allows unauthorized access and server takeover. The flaw stems from missing authentication checks on critical configuration routes, enabling attackers to modify server settings and exfiltrate sensitive information. This vulnerability has been actively exploited, with thousands of unauthorized requests detected. Affected versions are those prior to 1.83.0.
System administrators are urged to upgrade immediately to the latest version and implement security best practices, such as using unique master keys and restricting public internet access to administrative routes.