CVE-2026-12796 | BerriAI litellm up to 1.82.2 SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
A vulnerability has been found in BerriAI litellm up to 1.82.2 and classified as critical. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration.
This vulnerability is uniquely identified as CVE-2026-12796. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More