A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://gist.github.com/YLChen-007/3ace22e33e468d0166fe609c9fdf4184 | Exploit Third Party Advisory |
| https://vuldb.com/cve/CVE-2026-12799 | Third Party Advisory VDB Entry |
| https://vuldb.com/submit/811291 | Third Party Advisory Exploit VDB Entry |
| https://vuldb.com/vuln/372561 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/372561/cti | Permissions Required VDB Entry |
| https://vuldb.com/submit/811291 | Third Party Advisory Exploit VDB Entry |
Configurations
History
24 Jun 2026, 19:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gist.github.com/YLChen-007/3ace22e33e468d0166fe609c9fdf4184 - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/cve/CVE-2026-12799 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/submit/811291 - Third Party Advisory, Exploit, VDB Entry | |
| References | () https://vuldb.com/vuln/372561 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/372561/cti - Permissions Required, VDB Entry | |
| CPE | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
| First Time |
Litellm
Litellm litellm |
22 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/submit/811291 - |
21 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-21 10:16
Updated : 2026-06-24 19:26
NVD link : CVE-2026-12799
Mitre link : CVE-2026-12799
CVE.ORG link : CVE-2026-12799
JSON object : View
Products Affected
litellm
- litellm
