CVE-2026-12795

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
References
Link Resource
https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3 Exploit Third Party Advisory
https://vuldb.com/cve/CVE-2026-12795 Third Party Advisory VDB Entry
https://vuldb.com/submit/811286 Third Party Advisory Exploit VDB Entry
https://vuldb.com/vuln/372557 Third Party Advisory VDB Entry
https://vuldb.com/vuln/372557/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-21 09:16

Updated : 2026-06-24 20:15


NVD link : CVE-2026-12795

Mitre link : CVE-2026-12795

CVE.ORG link : CVE-2026-12795


JSON object : View

Products Affected

litellm

  • litellm
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function