{"id":80848,"date":"2026-06-21T03:45:08","date_gmt":"2026-06-21T00:15:08","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-12770-berriai-litellm-admin-key-key_management_endpoints-py-improper-authorization\/"},"modified":"2026-06-21T03:45:08","modified_gmt":"2026-06-21T00:15:08","slug":"cve-2026-12770-berriai-litellm-admin-key-key_management_endpoints-py-improper-authorization","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-12770-berriai-litellm-admin-key-key_management_endpoints-py-improper-authorization\/","title":{"rendered":"CVE-2026-12770 &#8211; BerriAI litellm Admin Key key_management_endpoints.py improper authorization"},"content":{"rendered":"<p>CVE ID :CVE-2026-12770<\/p>\n<p>  Published : June 21, 2026, 12:15 a.m. | 1\u00a0hour, 28\u00a0minutes ago<\/p>\n<p>  Description :A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm\/proxy\/management_endpoints\/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-12770 Published : June 21, 2026, 12:15 a.m. | 1\u00a0hour, 28\u00a0minutes ago Description :A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm\/proxy\/management_endpoints\/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-80848","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/80848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=80848"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/80848\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=80848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=80848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=80848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}