Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3529 articles · 209755 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-12799EXPLOITED
berriai · litellm

BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization

Description

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

Affected Products

VendorProductVersions
berriailitellm1.82.0, 1.82.1, 1.82.2, main-latest (docker image ghcr.io/berriai/litellm:main-latest, repo digest ghcr.io/berriai/litellm@sha256:bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f)

References

  • https://vuldb.com/vuln/372561(vdb-entry, technical-description)
  • https://vuldb.com/vuln/372561/cti(signature, permissions-required)
  • https://vuldb.com/cve/CVE-2026-12799(third-party-advisory)
  • https://vuldb.com/submit/811291(third-party-advisory)
  • https://gist.github.com/YLChen-007/3ace22e33e468d0166fe609c9fdf4184(exploit)

Discussion (0)

Loading…

CVSS 3.14.3 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-285, CWE-266, CWE-94
PublishedJun 21, 2026
Last enriched75d ago
Tags
sandbox escapecode injectionregex bypassbytecode manipulationmitigationauthenticated API
Trending Score0
Source articles0
Independent0
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-59822EXPKEV
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
Trending: 127
MEDIUMCVE-2026-84377EXP
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Trending: 46
LOWCVE-2026-59819
LiteLLM: Local file read via request-supplied OIDC file references
LOWCVE-2026-59821EXPKEV
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
NONECVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 21, 2026
Discovered by ZDM
Jun 21, 2026
Actively Exploited
Jun 22, 2026
Exploit Available
Jun 22, 2026