CVE-2026-35029 | berriai litellm up to 1.82.x /config/update UI_LOGO_PATH authorization
A vulnerability, which was classified as critical, has been found in berriai litellm up to 1.82.x. This issue affects some unknown processing of the file /config/update. The manipulation of the argument UI_LOGO_PATH leads to incorrect authorization.
This vulnerability is documented as CVE-2026-35029. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.