CVE-2026-108574
Received Received - Intake

Authorization Bypass in LiteLLM Spend Tracking

Vulnerability report for CVE-2026-108574, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the component Spend Tracking. Executing a manipulation of the argument session_id can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 1.96.0 can resolve this issue. This patch is called 722d9ffa4f6c5ae15702ab9ab2c5f6bf1688308b. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 96 associated CPEs
Vendor Product Version / Range
BerriAI LiteLLM 1.0
BerriAI LiteLLM 1.1
BerriAI LiteLLM 1.2
BerriAI LiteLLM 1.3
BerriAI LiteLLM 1.4
BerriAI LiteLLM 1.5
BerriAI LiteLLM 1.6
BerriAI LiteLLM 1.7
BerriAI LiteLLM 1.8
BerriAI LiteLLM 1.9
BerriAI LiteLLM 1.10
BerriAI LiteLLM 1.11
BerriAI LiteLLM 1.12
BerriAI LiteLLM 1.13
BerriAI LiteLLM 1.14
BerriAI LiteLLM 1.15
BerriAI LiteLLM 1.16
BerriAI LiteLLM 1.17
BerriAI LiteLLM 1.18
BerriAI LiteLLM 1.19
BerriAI LiteLLM 1.20
BerriAI LiteLLM 1.21
BerriAI LiteLLM 1.22
BerriAI LiteLLM 1.23
BerriAI LiteLLM 1.24
BerriAI LiteLLM 1.25
BerriAI LiteLLM 1.26
BerriAI LiteLLM 1.27
BerriAI LiteLLM 1.28
BerriAI LiteLLM 1.29
BerriAI LiteLLM 1.30
BerriAI LiteLLM 1.31
BerriAI LiteLLM 1.32
BerriAI LiteLLM 1.33
BerriAI LiteLLM 1.34
BerriAI LiteLLM 1.35
BerriAI LiteLLM 1.36
BerriAI LiteLLM 1.37
BerriAI LiteLLM 1.38
BerriAI LiteLLM 1.39
BerriAI LiteLLM 1.40
BerriAI LiteLLM 1.41
BerriAI LiteLLM 1.42
BerriAI LiteLLM 1.43
BerriAI LiteLLM 1.44
BerriAI LiteLLM 1.45
BerriAI LiteLLM 1.46
BerriAI LiteLLM 1.47
BerriAI LiteLLM 1.48
BerriAI LiteLLM 1.49
BerriAI LiteLLM 1.50
BerriAI LiteLLM 1.51
BerriAI LiteLLM 1.52
BerriAI LiteLLM 1.53
BerriAI LiteLLM 1.54
BerriAI LiteLLM 1.55
BerriAI LiteLLM 1.56
BerriAI LiteLLM 1.57
BerriAI LiteLLM 1.58
BerriAI LiteLLM 1.59
BerriAI LiteLLM 1.60
BerriAI LiteLLM 1.61
BerriAI LiteLLM 1.62
BerriAI LiteLLM 1.63
BerriAI LiteLLM 1.64
BerriAI LiteLLM 1.65
BerriAI LiteLLM 1.66
BerriAI LiteLLM 1.67
BerriAI LiteLLM 1.68
BerriAI LiteLLM 1.69
BerriAI LiteLLM 1.70
BerriAI LiteLLM 1.71
BerriAI LiteLLM 1.72
BerriAI LiteLLM 1.73
BerriAI LiteLLM 1.74
BerriAI LiteLLM 1.75
BerriAI LiteLLM 1.76
BerriAI LiteLLM 1.77
BerriAI LiteLLM 1.78
BerriAI LiteLLM 1.79
BerriAI LiteLLM 1.80
BerriAI LiteLLM 1.81
BerriAI LiteLLM 1.82
BerriAI LiteLLM 1.83
BerriAI LiteLLM 1.84
BerriAI LiteLLM 1.85
BerriAI LiteLLM 1.86
BerriAI LiteLLM 1.87
BerriAI LiteLLM 1.88
BerriAI LiteLLM 1.89
BerriAI LiteLLM 1.90
BerriAI LiteLLM 1.91
BerriAI LiteLLM 1.92
BerriAI LiteLLM 1.93
BerriAI LiteLLM 1.94
BerriAI LiteLLM 1.95.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in BerriAI LiteLLM up to version 1.95.0. It affects the spend tracking feature in the proxy server, specifically the function ui_view_session_spend_logs. By manipulating the session_id argument, an attacker can bypass authorization checks and access spend data they are not permitted to view. The issue is remotely exploitable and a proof-of-concept exploit has been published.

Detection Guidance

Detecting this vulnerability requires checking if your LiteLLM instance is running a vulnerable version (up to 1.95.0). Inspect the version of LiteLLM in use and compare it against the patched version 1.96.0. Check logs for unauthorized access attempts to spend tracking endpoints like /key/spend/report, /user/spend/report, /team/spend/report, or /organization/spend/report.

Impact Analysis

If you use BerriAI LiteLLM versions up to 1.95.0, an attacker could exploit this to view sensitive spend data such as API key costs, token usage, and model-level breakdowns for other users, teams, or organizations. This could lead to unauthorized access to financial or operational information, potential data leaks, and misuse of billing or resource tracking data.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive user or organizational data. GDPR requires strict access controls and data protection for personal data, while HIPAA mandates safeguards for protected health information. Unauthorized exposure of spend logs may violate these regulations, leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies
  • Upgrade LiteLLM to version 1.96.0 or later immediately to address the authorization bypass flaw.
  • Review and restrict access to spend tracking endpoints to ensure only authorized users can query spend data.
  • Monitor logs for suspicious activity related to session_id manipulation or unauthorized access to spend reports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart