Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: secret-theft (3 articles)Clear

Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key

Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.

Check
Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
Affected
Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
Fix
Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.

Attackers probe LiteLLM AI gateways to steal cloud and model provider secrets

Attackers are actively probing LiteLLM deployments for an authorization flaw that turns a low-privilege account into full control of the AI gateway. Tracked as CVE-2026-35029 and affecting versions before 1.83.0, the flaw is a missing permission check on the configuration-update endpoint, so a read-only user can change settings reserved for administrators. LiteLLM sits between applications and model providers and stores provider API keys, database details, and admin credentials, making it a rich target. By abusing configuration writes, an attacker can extract secrets from server environment files and even reset the dashboard login to seize admin access. Researchers recorded thousands of probing requests, some directly attempting to read known secret files.

Check
Upgrade LiteLLM to 1.83.0 or later, restrict access to its control plane and configuration endpoints, and rotate any provider, cloud, or database secrets the gateway could expose.
Affected
Organizations running LiteLLM before 1.83.0 as an AI gateway (CVE-2026-35029); a low-privilege authenticated user can modify configuration, read environment secrets, and escalate to administrator, exposing stored model provider and cloud credentials.
Fix
Patch, segment and firewall the LiteLLM control plane away from untrusted users, enforce least privilege, store secrets outside reachable environment files, rotate exposed keys, and monitor configuration endpoints for unauthorized changes.

Attackers exploit critical Langflow and Rails flaws to harvest secrets

VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.

Check
Patch Langflow and Ruby on Rails to fixed versions now, and rotate any secrets an attacker could have read, including the Rails master key, database passwords, cloud credentials, and API keys.
Affected
Internet-facing Langflow servers (CVE-2026-0768) and Rails apps using Active Storage with libvips (CVE-2026-66066); attackers can run code as root or read files leaking the master key, cloud credentials, and API tokens.
Fix
Update both immediately, rotate exposed secrets, restrict internet exposure of Langflow, review logs for environment-variable probing and image-upload abuse, and treat any exposed instance as potentially credential-compromised.