CVE-2026-12795: Authentication Bypass in BerriAI litellm SSO Debug Flow (CVSS 7.3)
BerriAI's litellm, an open-source LLM proxy framework, contains an authentication bypass vulnerability in its Single Sign-On (SSO) debug flow. An unauthenticated remote attacker can manipulate the SSO debug endpoint to bypass authentication controls, gaining unauthorized access to the system. The vulnerability affects litellm versions up to and including 1.82.2, and exploit code has already been publicly disclosed.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.3 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-287, CWE-306
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-24
NVD description (verbatim)
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability resides in the SSO debug flow component (litellm/proxy/management_endpoints/ui_sso.py), specifically in how the json.dumps function processes SSO-related data without proper authentication validation. By exploiting inadequate input handling in the debug flow, an attacker can craft requests that bypass the intended authentication mechanism (CWE-287: Improper Authentication and CWE-306: Missing Authentication for Critical Function). The flaw allows remote exploitation with no special privileges or user interaction required, making it a network-accessible authentication bypass.
Business impact
Organizations deploying litellm as an API gateway or proxy layer face direct risk of unauthorized access to backend LLM services and potentially sensitive data processed by those models. This is particularly critical for enterprises using litellm to manage multi-tenant API access, as an attacker could impersonate legitimate users or bypass rate-limiting and billing controls. The public disclosure of exploit code elevates urgency, as malicious actors have functional attack paths ready for deployment. Affected systems should be treated as potentially compromised until patching is verified.
Affected systems
BerriAI litellm versions up to 1.82.2 are vulnerable. This includes any deployment where the SSO debug flow is enabled or accessible. Users running litellm as a reverse proxy, API gateway, or authentication layer for LLM backends are at highest risk. Verify your installed version immediately; the vendor was contacted early and patches are likely available or imminent.
Exploitability
Exploitation is straightforward and requires no authentication, special privileges, or user interaction. An attacker needs only network access to the litellm proxy endpoint and knowledge of the SSO debug flow endpoint structure. The attack can be executed remotely over HTTP/HTTPS. With public disclosure and likely-available proof-of-concept code, the exploitability window is active now. This is not a theoretical or difficult-to-exploit flaw.
Remediation
Upgrade litellm to a patched version beyond 1.82.2 immediately. Verify the specific patch version in the official BerriAI GitHub releases and security advisories. As an interim measure, if patching cannot be deployed immediately, restrict network access to the litellm proxy to trusted IP ranges only, disable or remove the SSO debug flow if it is not operationally necessary, and monitor authentication logs for anomalous access patterns or failed credential validation.
Patch guidance
Check the BerriAI litellm GitHub repository and official security advisories for the latest patched version. The vendor was contacted early, so a fix is likely available. Apply updates through your standard deployment pipeline (pip, Docker, etc.). After patching, restart all litellm instances and verify that the SSO authentication flow enforces proper credential validation. Test from both authorized and unauthorized contexts to confirm the fix is effective. Do not skip this step given the public exploit disclosure.
Detection guidance
Monitor litellm proxy logs for requests to SSO debug endpoints (/debug, /sso, or similar paths depending on your configuration) that originate from unexpected sources or that bypass normal authentication flows. Look for json.dumps-related errors or unusual serialization patterns in debug logs. Implement Web Application Firewall (WAF) rules to block or alert on requests to debug endpoints from external networks. Check for authentication logs showing successful access without corresponding valid credential presentation. Intrusion detection systems should flag HTTP requests to sensitive proxy paths from unauthenticated sources.
Why prioritize this
This vulnerability combines high CVSS score (7.3), network exploitability, public disclosure, and direct impact on authentication—a core security control. Any system using litellm for API gateway or multi-tenant LLM access should treat this as critical. The lack of KEV designation does not diminish urgency; public exploit code is available, making active exploitation likely in the wild. Prioritize patching within 24–48 hours for internet-facing deployments.
Risk score, explained
CVSS 7.3 (HIGH) reflects the confluence of network accessibility (AV:N), low attack complexity (AC:L), no privilege requirement (PR:N), no user interaction (UI:N), and impact across confidentiality, integrity, and availability (C:L/I:L/A:L). The score appropriately captures an authentication bypass that allows unauthorized access with moderate impact. Contextually, the public disclosure and immediate exploitability elevate real-world risk beyond the numerical score alone.
Frequently asked questions
What versions of litellm are affected?
Litellm versions up to and including 1.82.2 are vulnerable. Verify your installed version with `pip show litellm` or check your deployment manifest. Patch versions beyond 1.82.2 address this issue; consult the official BerriAI security advisory for the exact patched version number.
Is the SSO debug flow a required feature, or can we disable it?
The debug flow is typically an optional diagnostic and development tool. If your organization does not require it for ongoing operations, disabling it in your litellm configuration is a valid interim mitigation. Review your configuration file and consult BerriAI documentation for the appropriate setting to disable or restrict debug endpoints.
How can we detect if we've been exploited?
Check litellm proxy access logs for requests to debug or SSO endpoints from unexpected sources, and authentication logs for successful logins without valid credential submission. Look for authentication errors followed immediately by successful access, which may indicate bypass attempts. If you suspect compromise, review API access logs for unauthorized token usage or LLM service calls.
Do we need to reset user credentials after patching?
Yes. If your logs indicate possible unauthorized access, reset all API keys, SSO tokens, and user credentials as a precaution. Assume any system with network access to the unpatched proxy may have been compromised. Review recent access activity and rotate credentials even if no obvious exploitation is detected.
This analysis is provided for informational and defensive purposes. Verify all patch versions, product names, and vendor advisory details against official BerriAI security releases before deployment. This document does not constitute legal advice or official product support. Organizations should conduct their own vulnerability assessment based on their specific litellm deployment architecture and business context. No exploit code or weaponized proof-of-concept details are included; responsible disclosure principles have been observed. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10243HIGHSmart Parking System 1.0 Authentication Bypass – Remote Admin Access
- CVE-2026-10281HIGHEnderfga claw-orchestrator Authentication Bypass – Patch Available
- CVE-2026-10617HIGHGoClaw Webhook Authentication Bypass – Remote Exploitation
- CVE-2026-45567HIGHRoxy-WI Authentication Bypass in HAProxy/Nginx Management Interface
- CVE-2026-46827HIGHOracle E-Business Suite Payroll Remote Compromise – 8.8 CVSS
- CVE-2026-46903HIGHJD Edwards EnterpriseOne Tools Privilege Escalation Vulnerability (CVSS 8.8)
- CVE-2026-46916HIGHOracle Process Manufacturing Vulnerability (CVSS 8.8)
- CVE-2026-46921HIGHOracle Siebel CRM Cloud Manager Authentication Bypass – CVSS 8.8