Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

BerriAI LiteLLM SQL Injection (CVE-2026-42208)

Historical catalog analysis: CISA added this entry on May 08, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-42208 is a SQL injection vulnerability (CWE-89) identified in the BerriAI LiteLLM proxy. The flaw allows an attacker to execute unauthorized queries against the proxy’s database. This exposure could enable an actor to read or modify data, which may lead to unauthorized access to the proxy itself and the credentials it manages.

Exposure and applicability

This vulnerability affects organizations deploying BerriAI LiteLLM as a proxy for managing Large Language Model (LLM) interactions. The primary risk is centered on the integrity and confidentiality of the backend database used by the proxy. Because this component handles managed credentials, a successful injection could result in the compromise of API keys or other sensitive authentication tokens stored within the system.

Remediation priorities

Based on its inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog as of May 8, 2026, this vulnerability should be treated as a high-priority remediation task. Our analysis suggests the following priority sequence:

  1. Immediate Identification: Locate all instances of LiteLLM deployed across cloud and on-premises environments.
  2. Vendor Mitigation: Apply the specific mitigations provided by BerriAI.
  3. Cloud Configuration Review: For those utilizing cloud services, review configurations in alignment with BOD 22-01 guidance to ensure the proxy is not unnecessarily exposed to untrusted networks.
  4. Decommissioning: If vendor mitigations cannot be applied or are unavailable for a specific deployment, the product should be discontinued to eliminate the exposure path.

How to validate remediation

Verification must go beyond confirming a version number. To assure that the vulnerability has been mitigated, defenders should:

  • Verify Mitigation Application: Confirm that the vendor-specified patches or configuration changes have been successfully deployed across all affected nodes.
  • Database Access Audit: Review database logs for unauthorized query patterns or unexpected administrative changes that may have occurred prior to patching.
  • Credential Rotation: Because this vulnerability allows for the reading of managed credentials, we recommend rotating all API keys and secrets stored within LiteLLM after the fix is applied. A patch prevents future injection but does not invalidate credentials that may have already been exfiltrated.

Limits and open questions

It remains unknown whether this vulnerability has been utilized in ransomware campaigns. Additionally, while vendor mitigations address the SQL injection vector, residual risk may remain if the underlying database permissions are overly permissive (e.g., the proxy running as a database superuser). Defenders should evaluate the principle of least privilege for the database service account to limit the potential impact of any future injection flaws.

Source and editorial note

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability · Source date: May 08, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: May 11, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 12, 2026 at 00:09 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment