Record summary

CVE-2026-12773 has a selected CVSS score of 6.9 (medium).

Description

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus
CVE List1.59.0affected
1.59.1affected
1.59.2affected
1.59.3affected
1.59.4affected
1.59.5affected
1.59.6affected
1.59.7affected
1.59.8affected

Exploit Intelligence

Browse Red Hat / Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Ansible Automation Platform 2

Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Ansible Automation Platform 2

Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9

Default status: unaffected

CVE ListVersion data not supplied

References

9
VDB-372515 | BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authenticationvdb entryTechnical description
https://vuldb.com/vuln/372515