CVE-2026-42208 — SQL Injection in Lightspeed-chatbot-rhel9
Severity
9.8CRITICAL
No vectorEPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
Latest updateApr 29
Description
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://webflow.sysdig.com/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure
Affected Packages4 packages
🔴Vulnerability Details
1📋Vendor Advisories
1🕵️Threat Intelligence
2💬Community
1Bugzilla▶
CVE-2026-42208 LiteLLM: LiteLLM: Unauthorized data access and modification via SQL injection↗2026-04-29