CVE-2026-59822
Published Jul 8, 2026
Last updated 14 days ago
AI description
CVE-2026-59822 describes an authentication bypass vulnerability found in LiteLLM, an AI Gateway/proxy server, affecting all versions prior to 1.84.0. The flaw exists within LiteLLM's MCP Streamable HTTP endpoint. An unauthenticated attacker can exploit this vulnerability by providing a fabricated Authorization header. This action triggers an OAuth2 passthrough fallback mechanism that replaces a failed LiteLLM key validation with an empty `UserAPIKeyAuth()` object, thereby granting unauthorized access to MCP tooling and its associated services.
- Description
- LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- litellm
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 8.2
- Impact score
- 4.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Severity
- HIGH
Data from CISA
- Vulnerability name
- BerriAI LiteLLM Improper Authentication Vulnerability
- Exploit added on
- Sep 2, 2026
- Exploit action due
- Sep 16, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-287
- Hype score
- Not currently trending
CISA KEV: attackers are chaining CVE-2026-59822 (LiteLLM MCP auth bypass) with CVE-2026-48710 (Starlette host header) for unauthenticated RCE on AI gateways. Qilin ransomware linked. Federal patch deadline Sept 16. Inventory your AI gateways. #InfoSec #ZeroDay #AISecurity
@infrasecserv
7 Sept 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Your AI gateway is attack surface. CISA added LiteLLM's MCP auth bypass (CVE-2026-59822) to KEV. A fabricated Bearer token opened an authenticated session. Attackers are stealing LLM provider keys. Fix: v1.84.0+ #CyberSecurity #AppSec #OWASP https://t.co/K5ojVIs1FR https://t.c
@OWASPHyderabad
7 Sept 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
AI インフラを標的化する MCP の欠陥:RCE/ブラインド・プロンプト・インジェクション/認証情報窃取 https://t.co/zv9wVKvN2H AI インフラの急速な普及に伴い、各種の製品の安全性が問われています。具体的には、L
@iototsecnews
7 Sept 2026
132 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CISA KEV: CVE-2026-59822 LiteLLM MCP auth bypass. Fake bearer token opens an authenticated MCP session. Wiz saw probes against model enumeration endpoints. #cybersecurity #infosec #CISA #KEV #AIsecurity https://t.co/bxBtUIDzC2
@Caldura7
6 Sept 2026
42 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
🔴 LiteLLM / MCP açığı: CVE-2026-59822 — CISA KEV'e eklendi LiteLLM'in MCP Streamable HTTP endpoint'inde ciddi bir kimlik doğrulama atlatma açığı bulunuyordu. Saldırganın geçerli bir API/OAuth token'ına sahip olması gerekmiyor, savunmasız sürümlerde rastgel
@ridvanyagli
6 Sept 2026
557 Impressions
1 Retweet
10 Likes
4 Bookmarks
0 Replies
0 Quotes
PCMedicalist Signal · Sep 04 CVE-2026-59822--BerriAI LiteLLM: patch BerriAI LiteLLM and verify the fix held. Full brief 👇 #CyberSecurity #Vulnerability #InfoSec PCMedicalist · https://t.co/FgdnzXrZws https://t.co/od60HfLXc2
@PCMedicalist
4 Sept 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
LiteLLM's MCP endpoint accepted any Bearer token. A fabricated header sent key validation down a fallback that returned an empty auth object. CVE-2026-59822, on CISA's exploited list this week. Fixed in 1.84.0. Read the failure branch of your auth code, not the success one.
@0xAppSec
4 Sept 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Sep 03) CVE-2026-59822--BerriAI LiteLLM: patch BerriAI LiteLLM and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/T4Kfe17mgb
@PCMedicalist
4 Sept 2026
30 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
【緊急】LiteLLM に深刻な脆弱性(CVE-2026-59822 / CVSS v3.1 8.2) 未認証の攻撃者が偽のトークンでMCPセッションを確立できます。CISAが悪用確認済みリストに追加しました。 対処: 1.84.0以降へ更新してください。 htt
@ForsmileDNet
3 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Alerte CISA : Exploitation active de la faille critique d’authentification LiteLLM CVE-2026-59822. Elle permet à un attaquant non authentifié d’accéder aux outils MCP. #zoneantimalware https://t.co/6OuFiidTeo
@NicolasCoolman
3 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ
@foxbook
3 Sept 2026
263 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-59822: BerriAI LiteLLM MCP Authentication Bypass — Detection and Remed… "On September 2, 2026, CISA added CVE-2026-59822 to its Known Exploited…" 🔗 https://t.co/rfAgDBo8Ea #CyberSecurity #ThreatIntel #cve202659822 #critical #cisakev
@SecurityAr58409
3 Sept 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: Wiz honeypot data — AI-infra attacks doubled in 6mo; MCP servers in ~80% of environments, 5% net-exposed; CVE-2026-59822/CVE-2026-42271 chain to CVSS 10 unauth RCE. Unit 42: LLM safety refusal sits in ~50 of 350K neurons, trivially ablated. APT28's HOOKEDGE
@cloudsa
31 Aug 2026
302 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0432AF82-95FD-4358-9414-7B41889CEFD2",
"versionEndExcluding": "1.84.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]