CVE-2026-12773Exploit(litellm / litellm)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for litellm litellm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-303

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-06-21); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
litellm

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-06-21: 5Mentions · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-21: 2PoC Mentioned / Linked · 2026-06-25: 1Exploit Tool / Code · 2026-06-21: 1Technical Details · 2026-06-21: 3Technical Details · 2026-06-25: 106-2106-25
Signal classification4 categories
Exploit
233.3%
General
233.3%
Disclosure
116.7%
PoC
116.7%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-215
Disclosure1Exploit1General2PoC1
2026-06-251
Exploit1
Full discourse6 posts
  • CVE Official@CVE2026COIN
    Exploit

    🟠 HIGH (CVSS 7.3) — CVE-2026-12773 Published: 2026-06-21 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure. 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 🔗 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-12773 📚 References: • https://gist.github.com/YLChen-007/3cfaad10a69d7a15e4d4d458cb53309e • https://vuldb.com/cve/CVE-2026-12773 • https://vuldb.com/submit/811282 • https://vuldb.com/vuln/372515 #CVE #CyberSecurity #InfoSec #Vulnerability

    Post summary

    CVE-2026-12773 is a remotely exploitable improper authentication flaw in BerriAI litellm. A PoC / exploit script is publicly available, though no active in‑the‑wild incidents have been reported.

    0001072
    21 followersView on X
  • ThreatAft@ThreatAft
    Exploit

    🚨 CRITICAL: CVE-2026-12773 — LiteLLM MCP Proxy Auth Bypass CVSS 9.8. Unauthenticated remote attackers can bypass authentication via UserAPIKeyAuth function. Public exploit available. Affects 1.59.0-1.59.8 🔗 https://threataft.com/articles/cve-2026-12773-litellm-mcp-proxy-authentication-bypass #CyberSecurity #ThreatIntel #LiteLLM

    Post summary

    A critical CVE-2026-12773 allows unauthenticated remote attackers to bypass authentication in LiteLLM MCP Proxy via UserAPIKeyAuth, with a public exploit available and no known patch yet.

    0000085
    31 followersView on X
  • Upwind Security MDR@UpwindMDR
    PoC

    ⚠️MEDIUM - LiteLLM MCP Proxy authentication bypass (CVE-2026-12773) An auth bypass flaw in BerriAI LiteLLM (<=1.59.8) MCP Proxy allows remote unauthenticated attackers to bypass API key checks. Public PoC is available ,expect opportunistic scanning. 👉Affected: litellm <= 1.59.8

    Post summary

    A newly disclosed authentication bypass flaw (CVE‑2026‑12773) in BerriAI LiteLLM ≤1.59.8 has a publicly available PoC, prompting potential opportunistic scanning but no reported active exploitation.

    0000077
    223 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_a… https://www.cve.org/CVERecord?id=CVE-2026-12773 ----- Traducción: CVE-2026-12773 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-12773 has been announced as a weakness in BerriAI litellm up to version 1.59.8, affecting the UserAPIKeyAuth function, with no PoC, exploit code, or patch details provided.

    0000033
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_a… https://www.cve.org/CVERecord?id=CVE-2026-12773

    Post summary

    The text merely announces a weakness in BerriAI litellm version 1.59.8, without any details on exploitation or remediation.

    00000364
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-12773 Improper Authentication in BerriAI litellm MCP Proxy UserAPIKeyAuth Up to 1.59.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12773

    Post summary

    The post announces CVE‑2026‑12773 as an Improper Authentication flaw in BerriAI litellm MCP Proxy UserAPIKeyAuth up to version 1.59.8, but provides no PoC, exploit code, or mitigation details.

    0000052
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitellmlitellm---

Explore more