Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3529 articles · 209755 vulns · 37/41 feeds (7d)
← Back to list
6.3
CVE-2026-12796
berriai · litellm

BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Description

A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

Affected Products

VendorProductVersions
berriailitellm1.82.0, 1.82.1, 1.82.2

References

  • https://vuldb.com/vuln/372558(vdb-entry, technical-description)
  • https://vuldb.com/vuln/372558/cti(signature, permissions-required)
  • https://vuldb.com/cve/CVE-2026-12796(third-party-advisory)
  • https://vuldb.com/submit/811287(third-party-advisory)
  • https://gist.github.com/YLChen-007/5fa8af12e1b183674d7ca96d852fb697(exploit)

Discussion (0)

Loading…

CVSS 3.16.3 NONE
CISA KEV❌ No
Actively exploited❌ No
CWECWE-613
PublishedJun 21, 2026
Last enriched75d ago
Trending Score0
Source articles0
Independent0
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-59822EXPKEV
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Trending: 127
MEDIUMCVE-2026-84377EXP
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Trending: 46
LOWCVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
LOWCVE-2026-59821EXPKEV
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
NONECVE-2026-12799EXP
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 21, 2026
Discovered by ZDM
Jun 21, 2026