Tenant Isolation Bypass in BerriAI LiteLLM Affects Multiple Users
CVE-2026-89032

8.7HIGH

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-89032?

BerriAI LiteLLM prior to version 1.101.0-rc.1 exhibits a tenant isolation bypass vulnerability stemming from issues in the semantic cache layer. Authenticated users may exploit this flaw to access cached responses belonging to other tenants. By leveraging a metadata key mismatch, attackers can issue semantically similar queries to vulnerable API endpoints, leading to unintentional exposure of personally identifiable information (PII), financial data, and potentially sensitive source code. Additionally, this vulnerability allows attackers to manipulate front-end operations by delivering malicious payloads that execute under the victim's credentials, heightening the risks of data leakage and unauthorized actions within affected applications.

Affected Version(s)

litellm 0 < 1.101.0-rc.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tanguy Snoeck
.