ThreatsCloud & SaaSCriticalvLLM Inference Server Authentication Bypass Flaw CVE-2026-48746 Exposes Enterprise Model Endpoints Without API KeysCritical CVSS 9.1 flaw CVE-2026-48746 in vLLM allows unauthenticated remote attackers to bypass API key verification and access model completions due to URL normalization defects.Mei-Lin Chen·21 Sep 2026, 16:00 IST·14 min read