CVE-2026-108596: Openlit
Medium severity, CVSS 5.3.
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.
Affected products
- Openlit Openlit: from 2.1.0, up to and including 2.1.0
Published 2026-10-10. Last modified 2026-10-10.