CVE-2026-12795

medium

Description

A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

References

https://vuldb.com/vuln/372557/cti

https://vuldb.com/vuln/372557

https://vuldb.com/submit/811286

https://vuldb.com/cve/CVE-2026-12795

https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3

Details

Source: Mitre, NVD

Published: 2026-06-21

Updated: 2026-06-21

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium