CVE-2026-12795: BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/managementendpoints/uisso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12795?
The severity of CVE-2026-12795 is rated high with a CVSS score of 7.3.
How do I fix CVE-2026-12795?
To fix CVE-2026-12795, update the BerriAI litellm package to version 1.82.3 or later.
What impact does CVE-2026-12795 have on my application?
CVE-2026-12795 allows for missing authentication in the SSO Debug Flow, which could lead to unauthorized access.
Can CVE-2026-12795 be exploited remotely?
Yes, CVE-2026-12795 can be exploited remotely, allowing attackers to manipulate the application.
Which component is affected by CVE-2026-12795?
CVE-2026-12795 affects the json.dumps function in the SSO Debug Flow of the BerriAI litellm package.