CVE-2026-12795

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
References
Link Resource
https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3 Exploit Third Party Advisory
https://vuldb.com/cve/CVE-2026-12795 Third Party Advisory VDB Entry
https://vuldb.com/submit/811286 Third Party Advisory Exploit VDB Entry
https://vuldb.com/vuln/372557 Third Party Advisory VDB Entry
https://vuldb.com/vuln/372557/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

History

24 Jun 2026, 20:15

Type Values Removed Values Added
CPE cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*
First Time Litellm
Litellm litellm
References () https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3 - () https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3 - Exploit, Third Party Advisory
References () https://vuldb.com/cve/CVE-2026-12795 - () https://vuldb.com/cve/CVE-2026-12795 - Third Party Advisory, VDB Entry
References () https://vuldb.com/submit/811286 - () https://vuldb.com/submit/811286 - Third Party Advisory, Exploit, VDB Entry
References () https://vuldb.com/vuln/372557 - () https://vuldb.com/vuln/372557 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/372557/cti - () https://vuldb.com/vuln/372557/cti - Permissions Required, VDB Entry

21 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-21 09:16

Updated : 2026-06-24 20:15


NVD link : CVE-2026-12795

Mitre link : CVE-2026-12795

CVE.ORG link : CVE-2026-12795


JSON object : View

Products Affected

litellm

  • litellm
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function