CVE-2026-12772Disclosure(litellm / litellm)

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-21: 3Technical Details · 2026-06-21: 206-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12772 A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the … https://www.cve.org/CVERecord?id=CVE-2026-12772

    Post summary

    A CVE-2026-12772 flaw affecting BerriAI's Litellm up to version 1.82.2 is disclosed, impacting the authenticate_user function. No PoC, exploit, patch, or active exploitation details are provided.

    00010593
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12772 A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the … https://www.cve.org/CVERecord?id=CVE-2026-12772 ----- Traducción: CVE-2026-12772 Se … http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-12772) affecting BerriAI litellm up to 1.82.2 has been identified, targeting the authenticate_user function; no further exploit, patch, or technical detail information is provided.

    0000033
    88 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12772 Session Expiration Vulnerability in BerriAI litellm PROXY_ADMIN Database API Key Generator https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12772

    Post summary

    Announces a newly disclosed session expiration vulnerability in BerriAI litellm’s PROXY_ADMIN database API key generator, with no details on exploitation, patches, or PoC.

    0000061
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more