CVE-2026-40217 Privilege Escalation Vulnerability affecting AI
Evidence indicates that the affected technology is affected by privilege escalation. Reported affected versions include v1.83.3.rc.1.
DEVELOPING
What Happened
Evidence indicates that the affected technology is affected by privilege escalation. Reported affected versions include v1.83.3.rc.1.
Why This Matters
The evidence matters to defenders using AI Flaw Exposes because it could allow an attacker to gain additional privileges.
Recommended Action
Upgrade litellm to 1.83.10 or later. Identify deployments of AI Flaw Exposes matching the evidenced affected versions: v1.83.3.rc.1.
Exposure
Oct 01, 2025 05:30
Jun 15, 2026 05:30
Exploitation status: UNKNOWN
Affected versions: v1.83.3.rc.1
Primary entities:
Authoritative Intelligence
Timeline
-
Incident first seen
Oct 01, 2025 05:30BugSkan first recorded this incident.
-
Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover - The Hacker News
Oct 01, 2025 05:30thehackernews.com ยท Vulnerability
-
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers - The Hacker News
Jun 15, 2026 05:30thehackernews.com ยท Vulnerability
-
Latest observed development
Jun 15, 2026 05:30Most recent source or update associated with this incident.
-
Material change
Aug 18, 2026 14:29affected versions updated
-
Material change
Aug 18, 2026 14:29why it matters updated
-
Material change
Aug 18, 2026 14:29severity 5.0 -> 10.0
Sources
thehackernews.com ยท Oct 01, 2025 05:30
A critical vulnerability, CVE-2025-10725 (CVSS 9.9), allows authenticated, low-privileged attackers to escalate privileges to a full cluster administrator in Red Hat OpenShift AI. This flaw, due to an overly permissive ClusterRole, enables abuse of OpenShift Jobs to exfiltrate high-privilege ServiceAccount tokens, leading to a complete takeover of the hybrid cloud infrastructure.
Open publisher sourcethehackernews.com ยท Jun 15, 2026 05:30
A critical chain of three vulnerabilities (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) in LiteLLM allows a low-privilege internal user to bypass authorization, escalate privileges to full proxy admin, and achieve remote code execution (CVSS 9.9). This enables exfiltration of sensitive data like AI provider keys and credentials, and the ability to forge AI model responses in transit, requiring immediate upgrade to v1.83.14-stable or later.
Open publisher sourceWatchlist Match
Create an account to see which incidents overlap with the technologies you monitor.