Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Berry AI

Berry AI Vendor Cyber Rating & Cyber Score

berry-ai.com

Next to food, "Speed of Service" is the most impactful part of the customer experience at QSR restaurants. It literally determines customer loyalty, repeat visits, and how much profit a QSR location can make. The problem? Most QSR operators are stuck using legacy technology that requires them to guess how long customers ACTUALLY spend in line. Even worse, the operators have little to no visibility on how many people leave before they even place an order. That is literally money walking out the door. Berry AI provides QSR operators with affordable technology that gives operators actionable customer insights that are easy-to-digest, easy to act on, and consistently improves their bottom line. And for large-scale brands, Berry AI provides


Berry AI A.I CyberSecurity Scoring

Berry AI
Company Information
Website:https://www.berry-ai.com
Employees number:36
Number of followers:1,332
NAICS:5112
Industry Type:Software Development
Homepage:berry-ai.com
Berry AI Risk Score (AI oriented)
Between 700 and 749
logo
Berry AISoftware Development
Updated:
09/06/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Berry AI Global Score (TPRM)
xxxx
logo
Berry AISoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Berry AI
Berry AIModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
751Before Incident
Vulnerability
01 Apr 2026Berry AI
BerryAI: LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)

Critical Command Injection Flaw in LiteLLM AI Gateway Under Active Exploitation

748After Incident
CRITICAL-3
BER1781007894
Critical Command Injection Flaw in LiteLLM AI Gateway Under Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-42271, a command injection vulnerability in BerryAI’s LiteLLM open-source AI gateway, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. The flaw, disclosed in April 2026, affects organizations using LiteLLM a widely adopted library that standardizes interactions with multiple large language model (LLM) APIs under a single OpenAI-compatible interface. ### Vulnerability Details LiteLLM is used by developers and enterprises to manage API keys, route AI traffic, and avoid vendor lock-in, either as a Python SDK or a standalone proxy server. The vulnerability stems from improper input sanitization in two endpoints `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` which allowed authenticated users (including those with low-privilege API keys) to execute arbitrary commands on the host system. Exploitation required only a valid proxy API key, with no role-based access controls in place. ### Exploitation Risks & Attack Chain Initially, attackers needed a valid API key to exploit CVE-2026-42271, but researchers at Horizon3.ai discovered that the requirement could be bypassed by chaining it with CVE-2026-48710 ("BadHost"), an authentication bypass flaw in Starlette, the Python web framework underpinning LiteLLM. Successful exploitation enables: - Arbitrary command execution on the LiteLLM host - Theft of model provider credentials and API keys - Lateral movement into connected AI infrastructure - Compromise of downstream systems CVE-2026-48710 was patched in Starlette v1.0.1, while CVE-2026-42271 was addressed in LiteLLM v1.83.7, which introduced role-based restrictions (limiting test endpoint access to PROXY_ADMIN users) and updated Starlette dependencies. ### Mitigation & Federal Response Organizations using LiteLLM are urged to upgrade to v1.83.7 or, if immediate patching is not feasible, block access to the vulnerable MCP test endpoints and restrict network access to trusted segments. Credentials stored by the proxy should also be rotated. CISA has mandated U.S. federal civilian agencies to remediate the flaw by June 22, 2026. ### Broader Context This marks the second time in a month that LiteLLM has been targeted by attackers. In March 2026, threat group TeamPCP compromised BerryAI’s supply chain, publishing malicious LiteLLM versions on the Python Package Index (PyPI). No details have been released about the current exploitation campaigns or whether CVE-2026-48710 is being actively leveraged alongside the command injection flaw.
INCIDENT DETAILS -
TYPE
Command Injection
IMPACT
Data Compromised: Model provider credentials and API keysSystems Affected: LiteLLM host system, connected AI infrastructure, downstream systemsOperational Impact: Lateral movement, arbitrary command execution, potential compromise of AI services
DATA BREACH
Type Of Data Compromised: Model provider credentials, API keysSensitivity Of Data: High (AI infrastructure access)
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
751Before Incident
OCTOBER 2025
751Before Incident
SEPTEMBER 2025
751Before Incident
AUGUST 2025
751Before Incident
JULY 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Berry AI ?
?
What was Berry AI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Berry AI's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Berry AI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Berry AI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Berry AI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Berry AI Cyber Scoring History | Rankiteo