{"id":"CVE-2026-12795","aliases":["GHSA-j37q-q7p9-vpwm"],"title":"LiteLLM: SSO Debug Flow Has Improper Authentication","summary":"LiteLLM: SSO Debug Flow Has Improper Authentication","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","vendor":"litellm","product":"litellm","ecosystem":"pip","affected":["litellm <= 1.82.2"],"published":"2026-06-21","updated":"2026-09-10","sourceUpdated":"2026-09-10T22:45:04.140507172Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-j37q-q7p9-vpwm","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12795"},{"url":"https://gist.github.com/YLChen-007/9b13c75a3a73187a4082cc6df0b100d3"},{"url":"https://github.com/BerriAI/litellm"},{"url":"https://vuldb.com/cve/CVE-2026-12795"},{"url":"https://vuldb.com/submit/811286"},{"url":"https://vuldb.com/vuln/372557"},{"url":"https://vuldb.com/vuln/372557/cti"},{"url":"https://github.com/advisories/GHSA-j37q-q7p9-vpwm"}],"tags":["osv","pip","ghsa"],"epss":0.00795,"epssPercentile":0.54451,"cwe":["CWE-287"],"ingestedAt":"2026-09-10T23:08:11.245Z","slug":"CVE-2026-12795","body":"## Overview\n\nA vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.\n\n## Affected packages\n\n- `litellm <= 1.82.2`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":108720,"id":"CVE-2026-12795","ts":1789182839622,"field":"severity","old":"medium","new":"high"}]}