⌁AI·CYBER·BRIEF▌

#CVE-2026-93355

Vulnerabilities8 min read

No patch yet for a LiteLLM flaw that turns any valid login token into an admin account

CVE-2026-93355 lets anyone holding a valid token from your identity provider sign in as another LiteLLM user, including an admin. Affected through 1.102.1; the fix today is configuration.

CVE-2026-93355LiteLLMAI gateway