CVE detail
CVE-2026-12770
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 23781. It is recommended to apply a patch to fix this issue. The vendor was contacted early about this disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/vuln/372512/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 1:16 AM - https://vuldb.com/vuln/372512vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 1:16 AM - https://vuldb.com/submit/811279vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 1:16 AM - https://vuldb.com/cve/CVE-2026-12770vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 1:16 AM No excerpt available.
Exploitgithub.comJun 21, 2026, 1:16 AM- https://github.com/BerriAI/litellm/github.com
No excerpt available.
Exploitgithub.comJun 21, 2026, 1:16 AM No excerpt available.
Exploitgist.github.comJun 21, 2026, 1:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-12799CVSS 2.1 · Low
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/int…
- CVE-2026-12771CVSS 1.3 · Low
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handl…
- CVE-2026-17434CVSS 2.1 · Low
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. E…
- CVE-2026-17433CVSS 1.9 · Low
A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MC…
- CVE-2026-16224CVSS 5.3 · Medium
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The…
- CVE-2026-16199CVSS 2.1 · Low
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing…