Cyber Resilience

CVE-2026-12772

Litellm ≤ 1.82.3

Public PoC
Published
21 June 2026
Modified
24 June 2026
CVSS Score v4 2.1
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0026 18th percentile
Risk Priority 15 floored blend · peak EPSS

Summary

CVE-2026-12772 is a low-severity Insufficient Session Expiration (CWE-613) vulnerability in Litellm Litellm. Its CVSS base score is 2.1 (Low).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 18th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified map to AC-12 (Session Termination) and IA-11 (Re-authentication) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be…

more

initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Remote auth/session flaw in public-facing proxy API directly enables exploitation of the exposed application.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-12796Same product: Litellm Litellm
CVE-2026-12795Same product: Litellm Litellm
CVE-2026-40217Same product: Litellm Litellm
CVE-2026-12797Same product: Litellm Litellm
CVE-2026-12799Same product: Litellm Litellm
CVE-2026-12771Same product: Litellm Litellm
CVE-2026-35030Same product: Litellm Litellm
CVE-2025-45809Same product: Litellm Litellm
CVE-2026-42208Same product: Litellm Litellm
CVE-2026-59822Same product: Litellm Litellm

Affected Assets

litellm
litellm
≤ 1.82.3

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces session termination/expiration to address CWE-613 insufficient session expiration in the authenticate_user function.

prevent

Protects session authenticity and integrity, reducing impact of expired or manipulated sessions in the proxy auth component.

prevent

Requires periodic re-authentication, limiting the window of exposure from insufficient session expiration.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-01 mostly match
prevents

Credential lifecycle management directly includes enforcing session expiration to prevent reuse.

PR.AA-05 mostly match
prevents

Authorization policy enforcement and review covers terminating stale sessions to limit access scope.

PR.AA-03 partial match
prevents

Authentication mechanisms can incorporate session timeout checks but do not inherently address expiration policy.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Automatic termination of inactive sessions and limits on connection duration shrink the window during which a hijacked or unattended authenticated session can be exploited.

References