Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 11 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Berriai
Berriai litellm |
|
| Vendors & Products |
Berriai
Berriai litellm |
Sun, 11 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the component Spend Tracking. Executing a manipulation of the argument session_id can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 1.96.0 can resolve this issue. This patch is called 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b. The affected component should be upgraded. | |
| Title | BerriAI LiteLLM Spend Tracking spend_management_endpoints.py ui_view_session_spend_logs authorization | |
| First Time appeared |
Litellm
Litellm litellm |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Litellm
Litellm litellm |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-11T11:45:13.968Z
Reserved: 2026-10-10T15:37:46.507Z
Link: CVE-2026-108574
No data.
Status : Received
Published: 2026-10-11T12:16:52.990
Modified: 2026-10-11T12:16:52.990
Link: CVE-2026-108574
No data.
OpenCVE Enrichment
Updated: 2026-10-11T17:45:07Z