{"id":80863,"date":"2026-06-21T13:30:08","date_gmt":"2026-06-21T10:00:08","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-12799-berriai-litellm-incomplete-fix-cve-2025-0628-internal_user_endpoints-py-ui_view_users-improper-authorization\/"},"modified":"2026-06-21T13:30:08","modified_gmt":"2026-06-21T10:00:08","slug":"cve-2026-12799-berriai-litellm-incomplete-fix-cve-2025-0628-internal_user_endpoints-py-ui_view_users-improper-authorization","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-12799-berriai-litellm-incomplete-fix-cve-2025-0628-internal_user_endpoints-py-ui_view_users-improper-authorization\/","title":{"rendered":"CVE-2026-12799 &#8211; BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization"},"content":{"rendered":"<p>CVE ID :CVE-2026-12799<\/p>\n<p>  Published : June 21, 2026, 10 a.m. | 1\u00a0hour, 43\u00a0minutes ago<\/p>\n<p>  Description :A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm\/proxy\/management_endpoints\/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-12799 Published : June 21, 2026, 10 a.m. | 1\u00a0hour, 43\u00a0minutes ago Description :A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm\/proxy\/management_endpoints\/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to improper authorization. It is possible to &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-80863","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/80863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=80863"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/80863\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=80863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=80863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=80863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}