TechNewsReel
Live

Wiz Research: 1 in 10 Exposed LiteLLM Gateways Use Default Admin Keys

Security researchers found hundreds of AI gateways accessible via example keys, creating a path to cloud-level breaches.

TechNewsReel Newsroom · September 10, 2026

A significant portion of internet-facing LiteLLM gateways are vulnerable to administrative takeover due to the use of default credentials or a total lack of authentication. This exposure allows attackers to seize full control of the gateway, potentially leading to the theft of sensitive API keys and full system compromise.

In a February scan of 3,074 LiteLLM gateways identified via Shodan, Wiz Research found that 294 instances—nearly 10% of the sample—accepted the example admin key 'sk-1234' found in the software's setup guide. The research revealed that the vulnerability is often more severe than a simple default password; of those 294 vulnerable servers, 191 had no administrative key set at all, meaning any request was accepted as an administrative command. According to Wiz Research, "Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication at all."

The Role of AI Gateways

LiteLLM serves as an open-source AI gateway, providing a unified, OpenAI-compatible interface for more than 100 different large language model (LLM) providers. Because the software acts as a central hub between a company's internal applications and external model providers, it is designed to manage sensitive API keys, user data, and spending records in one place. This centralized architecture makes the gateway a high-value target, as a single point of failure can expose the credentials for multiple AI services simultaneously.

Risks of Administrative Exposure

The consequences of this authentication bypass extend far beyond the loss of AI credits, a practice known as "LLMjacking." Because the vulnerability grants administrative access, attackers can read all stored API keys and enumerate system users. More critically, Wiz Research reports that this access can be used to escalate privileges, allowing attackers to steal cloud Identity and Access Management (IAM) credentials and potentially achieve root-level remote code execution (RCE) on the host system. In such scenarios, a compromised LiteLLM instance becomes a beachhead for a full-scale breach of a company's entire cloud infrastructure.

Future Outlook

Organizations using LiteLLM are urged to verify that they have replaced all example keys and explicitly configured administrative authentication. While the immediate risk is tied to misconfiguration, the incident highlights a broader trend of "shadow AI" infrastructure being deployed without standard security hardening. Security teams should monitor for unauthorized administrative requests and ensure that gateways are not unnecessarily exposed to the public internet.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.