Sceawere

Vulnerability Detail

CVE-2026-108574UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LiteLLM Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
BerriAI
Product
LiteLLM
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the component Spend Tracking. Executing a manipulation of the argument session_id can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 1.96.0 can resolve this issue. This patch is called 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b. The affected component should be upgraded.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T12:16:52.990Z",
  "pubdate": "2026-10-11T12:16:52.990Z",
  "executiveSummary": "A critical authorization bypass vulnerability exists in BerriAI LiteLLM versions up to 1.95.0, specifically within the spend tracking functionality.\nThe flaw originates from improper handling of the session_id argument within the ui_view_session_spend_logs function.\nThis vulnerability allows a remote, unauthenticated, or unauthorized attacker to access spend logs associated with arbitrary sessions that they are not permitted to view.\nThe risk implication is high, as it permits the unauthorized disclosure of sensitive infrastructure usage data and financial spend metrics.\nExploitation is possible remotely and does not require sophisticated preconditions beyond the ability to interact with the affected proxy endpoint.\nThis flaw is effectively addressed by updating to version 1.96.0, which incorporates the security patch associated with commit 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b.",
  "technicalDetails": "The vulnerability resides within the file litellm/proxy/spend_tracking/spend_management_endpoints.py in the function ui_view_session_spend_logs. The root cause is a failure to properly validate the authorization context of the user when requesting spend log data based on the provided session_id parameter.\nIn the affected versions, the function processes the user-supplied session_id directly to retrieve and return session logs. Because there is inadequate verification to ensure that the requester has the appropriate permissions to access logs for the specific session_id provided, an attacker can manipulate this argument to access data outside their authorized scope.\nThe attack flow proceeds as follows: 1. An attacker identifies a target LiteLLM proxy instance that has Spend Tracking enabled. 2. The attacker crafts a request to the ui_view_session_spend_logs endpoint, passing a manipulated or targeted session_id as an argument. 3. The server-side logic fails to enforce a check to see if the authenticated requester owns or has administrative rights over the specified session_id. 4. The function proceeds to execute a database query or fetch operation using the unverified session_id. 5. The application returns the sensitive spend logs associated with the provided session_id to the attacker.\nThis vulnerability is classified as an authorization bypass because it circumvents the intended security controls that should restrict data access to authorized users or sessions only. The exposure is remote, as the proxy typically serves as an interface for LLM operations. Since the exploit code is publicly available, the risk of active exploitation is significant. Post-exploitation impact includes the unauthorized leakage of usage patterns, cost information, and potentially sensitive API session metadata, which may lead to further intelligence gathering for targeted attacks against the organization's LLM infrastructure. The security patch 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b addresses this by implementing proper authorization checks to ensure that the session_id being queried corresponds to the current requester's permitted scope."
}
CVE-2026-108574: LiteLLM Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere