CVE-2026-12772: BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration

Published Jun 21, 2026
·
Updated

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticateuser of the file litellm/proxy/auth/loginutils.py of the component PROXYADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

Affected Software

2 affected components
BerriAI LiteLLM<=1.82.2
LiteLLM LiteLLM<1.82.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the PROXY_ADMIN database API Key Generator (component: litellm/proxy/auth/login_utils.py authenticate_user) until a vendor-provided fix is available.

    PROXY_ADMIN database API Key Generator enabled = false
  2. Compensating control

    Restrict network access to the authenticate_user function in litellm/proxy/auth/login_utils.py (PROXY_ADMIN database API Key Generator) to trusted IPs or an internal management network only; block or firewall all other remote access to that endpoint.

  3. Operational

    Rotate and revoke all API keys issued by the PROXY_ADMIN database API Key Generator and invalidate active sessions; require re-authentication for affected accounts and applications.

  4. Operational

    Enable increased logging and alerting for calls to litellm/proxy/auth/login_utils.py authenticate_user and for anomalous session expirations; monitor for exploitation indicators and block or firewall IPs that exhibit exploit behavior.

Event History

Jun 21, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-12772?

The severity of CVE-2026-12772 is rated as medium with a score of 6.3.

2

How do I fix CVE-2026-12772?

To fix CVE-2026-12772, update BerriAI LiteLLM to the latest version that addresses this vulnerability.

3

What components are affected by CVE-2026-12772?

CVE-2026-12772 affects the function authenticate_user in the file litellm/proxy/auth/login_utils.py of the PROXY_ADMIN database API Key Generator.

4

What impact does CVE-2026-12772 have if exploited?

Exploiting CVE-2026-12772 may result in unintended session expiration for users authenticated through the affected component.

5

Is CVE-2026-12772 a remote vulnerability?

Yes, CVE-2026-12772 has a remote attack vector as indicated by the attack vector metric AV:N.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203