CVE-2026-108574 | BerriAI LiteLLM up to 1.95.0 Spend Tracking spend_management_endpoints.py ui_view_session_spend_logs session_id authorization

SecurityVulns

A vulnerability labeled as problematic has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the component Spend Tracking. Executing a manipulation of the argument session_id can lead to authorization bypass.

This vulnerability is registered as CVE-2026-108574. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More