vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Security discovered this chain, which involves an authorization bypass, privilege escalation, and a sandb… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation
threat-intel In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine This week’s cybersecurity news includes allegations of cover-ups by IBM and AT&T regarding foreign government-linked hacks, a data breach impacting the University of Oxford’s CareerConnect platform, and layoffs within Go… SecurityWeek · Jun 12, 2026 High CVE-2026-42271SOUNEUdata breachcyberattackddos
ransomware LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE A critical command injection vulnerability (CVE-2026-42271) in BerriAI’s LiteLLM has been actively exploited in the wild. The flaw, combined with a separate Starlette vulnerability (CVE-2026-48710), allows for unauthenti… The Hacker News · Jun 9, 2026 Critical CVE-2026-42271CVE-2026-48710CVE-2026-42208command injectionremote code executionunauthenticated