CVE-2026-12799 | BerriAI litellm up to 1.82.2 Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
A vulnerability was found in BerriAI litellm up to 1.82.2. It has been declared as problematic. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2026-12799. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More