Improper Authorization Vulnerability in BerriAI Litellm Product
CVE-2026-12771
Key Information:
Badges
What is CVE-2026-12771?
A security flaw has been identified in BerriAI's Litellm product, specifically affecting versions up to 1.82.2. The vulnerability resides in an unknown function within the file litellm/proxy/auth/user_api_key_auth.py, part of the M2M JWT Handler. This vulnerability allows for improper authorization, which could be exploited by an attacker remotely. Although the complexity of exploitation is considered high, the availability of public exploits may pose a significant risk to users of the affected software.
Affected Version(s)
litellm 1.82.0
litellm 1.82.1
litellm 1.82.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
