Litellm · Litellm · CVE-2026-93355
**Name of the Vulnerable Software and Affected Versions**
LiteLLM (affected versions not specified)
**Description**
A weak authentication issue exists in the JWT authentication flow. An attacker with a valid JSON Web Token (JWT) from the configured identity provider can authenticate as any existing user by exploiting an email-based fallback lookup. This occurs because the system fails to verify the `email verified` claim. By presenting a token with an unverified email address that matches a victim's account, an attacker can inherit the victim's role, including `proxy admin` privileges. This can lead to the permanent overwriting of the victim's stored identity binding, granting persistent unauthorized access to administrative endpoints that expose API keys and user management.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.