LiteLLMGHSA-6qr3-3g89-m4jj
LiteLLM: Admin Key Handler Has Improper Authorization
Low5.4CVE-2026-12770 · Published Jun 21, 2026 · updated Sep 10, 2026
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.63.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266
- Also known as
- CVE-2026-12770
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 21 | BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader | Low6.3 | No fix yet |
| Jun 21 | BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure | Low4.3 | No fix yet |
| Jun 21 | LiteLLM: improper authorization | Low6.3 | No fix yet |
| Jun 21 | BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: SSO Debug Flow Has Improper Authentication | Medium7.3 | No fix yet |
| Jun 21 | LiteLLM: MCP Proxy Has Improper Authentication | Medium7.3 | 1.84.0 |