CVE detail
CVE-2026-12773
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12773.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 21, 2026, 4:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2491112bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 21, 2026, 4:16 AM - https://access.redhat.com/security/cve/CVE-2026-12773access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 21, 2026, 4:16 AM - https://vuldb.com/vuln/372515/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 4:16 AM - https://vuldb.com/vuln/372515vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 4:16 AM - https://vuldb.com/submit/811282vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 4:16 AM - https://vuldb.com/cve/CVE-2026-12773vuldb.com
No excerpt available.
Exploitvuldb.comJun 21, 2026, 4:16 AM No excerpt available.
Exploitgist.github.comJun 21, 2026, 4:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-46389CVSS 10.0 · Critical
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0…
- CVE-2026-35579CVSS 8.2 · High
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QU…
- CVE-2025-63210CVSS 9.8 · Critical
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifyi…
- CVE-2024-8642CVSS 5.1 · Medium
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-b…
- CVE-2024-25157CVSS 6.5 · Medium
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to…
- CVE-2024-7593CVSS 9.8 · Critical
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the…