CVE-2026-12773: Improper Authentication in BerriAI litellm
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
AI Analysis
Technical Summary
This vulnerability involves improper authentication in the UserAPIKeyAuth function of the MCP Proxy component in BerriAI litellm versions up to 1.59.8. An attacker can manipulate the authentication process remotely, potentially bypassing intended access controls. The CVSS 4.0 base score is 6.9 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and low to limited impact on confidentiality, integrity, and availability. The vendor was notified early, but no official fix or remediation level has been published. The vulnerability is documented by Red Hat but without explicit patch or mitigation instructions.
Potential Impact
Successful exploitation allows an attacker to bypass authentication controls remotely, potentially gaining unauthorized access to the affected component. The impact on confidentiality, integrity, and availability is rated as low to limited. No known exploits are reported in the wild at this time, but public exploit code exists.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is documented, users should monitor the vendor advisory for updates. Until a patch is available, restrict network access to the affected component where possible to reduce exposure.
CVE-2026-12773: Improper Authentication in BerriAI litellm
Description
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
CVSS v4.0
Score 6.9medium
Affected software
pkg:pypi/litellmcpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper authentication in the UserAPIKeyAuth function of the MCP Proxy component in BerriAI litellm versions up to 1.59.8. An attacker can manipulate the authentication process remotely, potentially bypassing intended access controls. The CVSS 4.0 base score is 6.9 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, and low to limited impact on confidentiality, integrity, and availability. The vendor was notified early, but no official fix or remediation level has been published. The vulnerability is documented by Red Hat but without explicit patch or mitigation instructions.
Potential Impact
Successful exploitation allows an attacker to bypass authentication controls remotely, potentially gaining unauthorized access to the affected component. The impact on confidentiality, integrity, and availability is rated as low to limited. No known exploits are reported in the wild at this time, but public exploit code exists.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is documented, users should monitor the vendor advisory for updates. Until a patch is available, restrict network access to the affected component where possible to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-20T09:26:26.143Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-12773","vendor":"Red Hat"}]
Threat ID: 6a3760119c760d8add6c0198
Added to database: 06/21/2026, 03:52:49 UTC
Last enriched: 07/15/2026, 08:27:30 UTC
Last updated: 08/04/2026, 19:57:16 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.