{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47101.json"
      }
    ],
    "title": "litellm: LiteLLM: Privilege escalation via API key generation with insufficient permission validation",
    "tracking": {
      "current_release_date": "2026-06-30T15:43:13+00:00",
      "generator": {
        "date": "2026-06-30T15:43:13+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.1"
        }
      },
      "id": "CVE-2026-47101",
      "initial_release_date": "2026-05-21T20:33:30.163000+00:00",
      "revision_history": [
        {
          "date": "2026-05-21T20:33:30.163000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-30T15:30:59+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T15:43:13+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Exploit Intelligence",
                "product": {
                  "name": "Exploit Intelligence",
                  "product_id": "exploit_intelligence",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:exploit_intelligence:0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Exploit Intelligence"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Ansible Automation Platform 2",
                "product": {
                  "name": "Red Hat Ansible Automation Platform 2",
                  "product_id": "red_hat_ansible_automation_platform_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Ansible Automation Platform 2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "product": {
              "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_id": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/vulnerability-analysis-rhel9?repository_url=registry.redhat.io/exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "product": {
              "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_id": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "product": {
              "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
              "product_id": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/lightspeed-chatbot-rhel9?repository_url=registry.redhat.io/ansible-automation-platform-27/lightspeed-chatbot-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-llama-stack-core-rhel9",
            "product": {
              "name": "rhoai/odh-llama-stack-core-rhel9",
              "product_id": "rhoai/odh-llama-stack-core-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-llama-stack-core-rhel9?repository_url=registry.redhat.io/rhoai/odh-llama-stack-core-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-mlflow-rhel9",
            "product": {
              "name": "rhoai/odh-mlflow-rhel9",
              "product_id": "rhoai/odh-mlflow-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-mlflow-rhel9?repository_url=registry.redhat.io/rhoai/odh-mlflow-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
            "product": {
              "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
              "product_id": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-trustyai-garak-lls-provider-dsp-rhel9?repository_url=registry.redhat.io/rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence",
          "product_id": "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
        },
        "product_reference": "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
        "relates_to_product_reference": "exploit_intelligence"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-26/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9"
        },
        "product_reference": "ansible-automation-platform-26/lightspeed-chatbot-rhel9",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ansible-automation-platform-27/lightspeed-chatbot-rhel9 as a component of Red Hat Ansible Automation Platform 2",
          "product_id": "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9"
        },
        "product_reference": "ansible-automation-platform-27/lightspeed-chatbot-rhel9",
        "relates_to_product_reference": "red_hat_ansible_automation_platform_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9"
        },
        "product_reference": "rhoai/odh-llama-stack-core-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-mlflow-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9"
        },
        "product_reference": "rhoai/odh-mlflow-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
        },
        "product_reference": "rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-47101",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "discovery_date": "2026-05-21T21:00:54.938003+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        },
        {
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2480635"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in LiteLLM. An authenticated internal user can exploit this vulnerability by creating API keys that grant access to routes beyond their assigned role. This occurs because the system fails to verify if the specified allowed_routes for the API key align with the user's actual permissions. Consequently, a malicious internal user can achieve full privilege escalation, gaining administrative access (proxy_admin) and bypassing role-based access controls.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "litellm: LiteLLM: Privilege escalation via API key generation with insufficient permission validation",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability is rated Important because an authenticated LiteLLM proxy user with the internal_user role may be able to create API keys that grant access to admin-only routes, escalating privileges to proxy_admin level.\n\nExploitation requires network access to a LiteLLM proxy instance and valid credentials for a non-admin user account. Products that bundle litellm only as a client library, or that do not expose the LiteLLM proxy management API to untrusted users, have reduced exposure. Affected packages should be updated to litellm 1.83.14 or later when fixes are released.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
        ],
        "known_not_affected": [
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
          "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-47101"
        },
        {
          "category": "external",
          "summary": "RHBZ#2480635",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480635"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-47101",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47101"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-47101",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47101"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f",
          "url": "https://gist.github.com/13ph03nix/9ec616e1fdc77b3673509c60206e827f"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/commit/2220f3076ac89bd2a2e3439acf57dcfbec2434c9",
          "url": "https://github.com/BerriAI/litellm/commit/2220f3076ac89bd2a2e3439acf57dcfbec2434c9"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/commit/5190bd07eb23a037745d86328096f54378f1614a",
          "url": "https://github.com/BerriAI/litellm/commit/5190bd07eb23a037745d86328096f54378f1614a"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c",
          "url": "https://github.com/BerriAI/litellm/commit/d910a95661fce3cdd36f3b06c03ecf9c46c6457c"
        },
        {
          "category": "external",
          "summary": "https://github.com/BerriAI/litellm/releases/tag/v1.83.14-stable",
          "url": "https://github.com/BerriAI/litellm/releases/tag/v1.83.14-stable"
        },
        {
          "category": "external",
          "summary": "https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9",
          "url": "https://huntr.com/bounties/8e75edfb-ff05-4e63-bfca-2d93d03fb3b9"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-api-key-generation",
          "url": "https://www.vulncheck.com/advisories/litellm-privilege-escalation-via-api-key-generation"
        }
      ],
      "release_date": "2026-05-21T20:33:30.163000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Update the litellm package to version 1.83.14 or later.\n\nUntil updated builds are available, restrict LiteLLM proxy deployments so only trusted administrators can access key-generation and management routes. Audit existing API keys for allowed_routes grants that exceed the creating user role, and rotate keys where unauthorized admin-route access is found.",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "exploit_intelligence:exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-26/lightspeed-chatbot-rhel9",
            "red_hat_ansible_automation_platform_2:ansible-automation-platform-27/lightspeed-chatbot-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-llama-stack-core-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-mlflow-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9"
          ]
        }
      ],
      "title": "litellm: LiteLLM: Privilege escalation via API key generation with insufficient permission validation"
    }
  ]
}