Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: authorization-bypass (2 articles)Clear

Attackers probe LiteLLM AI gateways to steal cloud and model provider secrets

Attackers are actively probing LiteLLM deployments for an authorization flaw that turns a low-privilege account into full control of the AI gateway. Tracked as CVE-2026-35029 and affecting versions before 1.83.0, the flaw is a missing permission check on the configuration-update endpoint, so a read-only user can change settings reserved for administrators. LiteLLM sits between applications and model providers and stores provider API keys, database details, and admin credentials, making it a rich target. By abusing configuration writes, an attacker can extract secrets from server environment files and even reset the dashboard login to seize admin access. Researchers recorded thousands of probing requests, some directly attempting to read known secret files.

Check
Upgrade LiteLLM to 1.83.0 or later, restrict access to its control plane and configuration endpoints, and rotate any provider, cloud, or database secrets the gateway could expose.
Affected
Organizations running LiteLLM before 1.83.0 as an AI gateway (CVE-2026-35029); a low-privilege authenticated user can modify configuration, read environment secrets, and escalate to administrator, exposing stored model provider and cloud credentials.
Fix
Patch, segment and firewall the LiteLLM control plane away from untrusted users, enforce least privilege, store secrets outside reachable environment files, rotate exposed keys, and monitor configuration endpoints for unauthorized changes.

DifyTap flaws let attackers read other tenants' AI chats on Dify

Zafran Security disclosed four vulnerabilities, collectively named DifyTap, in Dify, a popular open-source platform for building AI agents and workflows. Two are critical, two need no authentication, and three allow cross-tenant access on Dify's multi-tenant cloud, meaning one customer could quietly read another's private AI conversations and model responses, a covert exfiltration channel. The flaws include an authorization bypass that exposes any application's trace data (CVE-2026-41947), a path traversal into the internal Plugin Daemon API (CVE-2026-41948), and a file-preview authorization bypass (CVE-2026-41949). Most were fixed in Dify 1.14.2, but the path-traversal flaw remains unpatched pending the next release.

Check
Determine whether your organization uses Dify, self-hosted or on its cloud, identify the running version, and review whether AI conversations or application data could have been accessed across tenant or user boundaries.
Affected
Dify deployments before version 1.14.2 (CVE-2026-41947, CVE-2026-41949) and all versions for the still-unpatched path traversal (CVE-2026-41948); multi-tenant and cloud setups face cross-tenant AI-chat exposure.
Fix
Update Dify to 1.14.2 or later now, watch for the forthcoming fix for the path-traversal flaw, restrict access to Dify's internal Plugin Daemon, and avoid putting sensitive data in shared multi-tenant instances.