Back to overview

CVE-2026-12773

HIGH
7.3
CVSS 3.1
Description
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

Metadata

CVE ID
CVE-2026-12773
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-20 09:26 UTC
Published
2026-06-21 03:15 UTC
Last updated
2026-06-21 03:15 UTC
Primary CWE
CWE-287
Improper Authentication
Vendor / Product
BerriAI / litellm
Sources
cve.org  ·  NVD

Severity & Metrics

7.3 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
BerriAI litellm 1.59.0, 1.59.1, 1.59.2, 1.59.3 …
Weakness (CWE)
CWESourceDescription
CWE-287 cna Improper Authentication
CVSS scores (4)
ScoreSeverityVersionSourceVector
7.5 N/D 2.0 cna AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
7.3 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
7.3 HIGH 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
References (5)
Back to overview