Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

SQL Injection in BerriAI LiteLLM (CVE‑2026‑42208) Added to CISA KEV Catalog – Active Exploitation Threatens Enterprises

CISA has added CVE‑2026‑42208, a SQL‑injection vulnerability in BerriAI LiteLLM, to its Known Exploited Vulnerabilities catalog. The flaw is being actively leveraged by threat actors, exposing organizations that rely on the AI inference service to data compromise and service disruption. TPRM teams should treat this as a high‑priority remediation item.

LiveThreat™ Intelligence · 📅 May 08, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

SQL Injection in BerriAI LiteLLM (CVE‑2026‑42208) Added to CISA KEV Catalog – Active Exploitation Threatens Enterprises

What It Is – A newly disclosed SQL‑injection flaw (CVE‑2026‑42208) affects BerriAI LiteLLM, an AI‑driven large‑language‑model inference service. The vulnerability allows an unauthenticated attacker to inject arbitrary SQL commands into the backend database, potentially exposing or modifying data.

Exploitability – CISA’s KEV Catalog entry confirms that the vulnerability is being actively exploited in the wild. No public proof‑of‑concept is required; threat actors are already leveraging it. The CVSS score (not yet published) is expected to be ≥ 7.5, placing it in the High severity range.

Affected Products – BerriAI LiteLLM (all versions prior to the vendor‑issued patch). The service is typically delivered as a cloud‑hosted API used by SaaS platforms, internal applications, and third‑party integrations.

TPRM Impact –

  • Third‑party AI services embedded in critical business workflows become a direct attack surface.
  • A successful exploit can lead to unauthorized data access, manipulation of model outputs, or lateral movement into downstream systems.

Recommended Actions –

  • Prioritize remediation of CVE‑2026‑42208 across all environments that consume BerriAI LiteLLM.
  • Apply the vendor‑released patch or, if unavailable, block outbound traffic to the vulnerable endpoint until mitigation is in place.
  • Conduct a rapid inventory of all applications and services that integrate the LiteLLM API to assess exposure.
  • Update vulnerability‑management tooling to flag KEV‑listed CVEs as “high‑priority” for remediation.
  • Review and harden input validation and parameterized query usage in any custom wrappers around the LiteLLM API.

Source: CISA Advisory – CISA Adds One Known Exploited Vulnerability to Catalog (May 08 2026)

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →