CVE-2026-12771

MEDIUM

BerriAI litellm M2M JWT user_api_key_auth.py improper authorization

Title source: cna
STIX 2.1

Description

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

References (5)

Core 5
Core References
Vdb Entry vdb-entry
VDB-372513 | BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
https://vuldb.com/vuln/372513
Signature, Permissions Required signature permissions-required
VDB-372513 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/372513/cti
Third Party Advisory third-party-advisory
CVE-2026-12771 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-12771
Third Party Advisory third-party-advisory
Submit #811280 | litellm <= 1.82.2 Improper Authorization (CWE-285)
https://vuldb.com/submit/811280

Scores

CVSS v3 5.0
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

Details

CWE
CWE-266 CWE-285
Status published
Products (3)
BerriAI/litellm 1.82.0
BerriAI/litellm 1.82.1
BerriAI/litellm 1.82.2
Published Jun 21, 2026
Tracked Since Jun 21, 2026