Threats·Cloud & SaaSHighLiteLLM JWT Email Fallback Lets Unverified Login Tokens Take Over Proxy Admin Accounts, With No Fix ReleasedLiteLLM CVE-2026-93355 lets a signed JWT with an unverified email claim seize any account, including proxy_admin. No fix yet; cache-leak and SSRF CVEs patched.Aisha Noor3 Oct 20266 min read