CVE-2026-59822

Published Jul 8, 2026

Last updated 14 days ago

Exploit knownCVSS high 8.8
MCP
Jwt
Container Security
LiteLLM
OpenAI

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-59822 describes an authentication bypass vulnerability found in LiteLLM, an AI Gateway/proxy server, affecting all versions prior to 1.84.0. The flaw exists within LiteLLM's MCP Streamable HTTP endpoint. An unauthenticated attacker can exploit this vulnerability by providing a fabricated Authorization header. This action triggers an OAuth2 passthrough fallback mechanism that replaces a failed LiteLLM key validation with an empty `UserAPIKeyAuth()` object, thereby granting unauthorized access to MCP tooling and its associated services.

Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Source
security-advisories@github.com
NVD status
Analyzed
Products
litellm

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
4.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
BerriAI LiteLLM Improper Authentication Vulnerability
Exploit added on
Sep 2, 2026
Exploit action due
Sep 16, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security-advisories@github.com
CWE-287

Social media

Hype score
Not currently trending
  1. CISA KEV: attackers are chaining CVE-2026-59822 (LiteLLM MCP auth bypass) with CVE-2026-48710 (Starlette host header) for unauthenticated RCE on AI gateways. Qilin ransomware linked. Federal patch deadline Sept 16. Inventory your AI gateways. #InfoSec #ZeroDay #AISecurity

    @infrasecserv

    7 Sept 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  2. Your AI gateway is attack surface. CISA added LiteLLM's MCP auth bypass (CVE-2026-59822) to KEV. A fabricated Bearer token opened an authenticated session. Attackers are stealing LLM provider keys. Fix: v1.84.0+ #CyberSecurity #AppSec #OWASP https://t.co/K5ojVIs1FR https://t.c

    @OWASPHyderabad

    7 Sept 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. AI インフラを標的化する MCP の欠陥:RCE/ブラインド・プロンプト・インジェクション/認証情報窃取 https://t.co/zv9wVKvN2H AI インフラの急速な普及に伴い、各種の製品の安全性が問われています。具体的には、L

    @iototsecnews

    7 Sept 2026

    132 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA KEV: CVE-2026-59822 LiteLLM MCP auth bypass. Fake bearer token opens an authenticated MCP session. Wiz saw probes against model enumeration endpoints. #cybersecurity #infosec #CISA #KEV #AIsecurity https://t.co/bxBtUIDzC2

    @Caldura7

    6 Sept 2026

    42 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  5. 🔴 LiteLLM / MCP açığı: CVE-2026-59822 — CISA KEV'e eklendi LiteLLM'in MCP Streamable HTTP endpoint'inde ciddi bir kimlik doğrulama atlatma açığı bulunuyordu. Saldırganın geçerli bir API/OAuth token'ına sahip olması gerekmiyor, savunmasız sürümlerde rastgel

    @ridvanyagli

    6 Sept 2026

    557 Impressions

    1 Retweet

    10 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  6. PCMedicalist Signal · Sep 04 CVE-2026-59822--BerriAI LiteLLM: patch BerriAI LiteLLM and verify the fix held. Full brief 👇 #CyberSecurity #Vulnerability #InfoSec PCMedicalist · https://t.co/FgdnzXrZws https://t.co/od60HfLXc2

    @PCMedicalist

    4 Sept 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. LiteLLM's MCP endpoint accepted any Bearer token. A fabricated header sent key validation down a fallback that returned an empty auth object. CVE-2026-59822, on CISA's exploited list this week. Fixed in 1.84.0. Read the failure branch of your auth code, not the success one.

    @0xAppSec

    4 Sept 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔐 Daily Security & Standards Brief (Sep 03) CVE-2026-59822--BerriAI LiteLLM: patch BerriAI LiteLLM and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/T4Kfe17mgb

    @PCMedicalist

    4 Sept 2026

    30 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 【緊急】LiteLLM に深刻な脆弱性(CVE-2026-59822 / CVSS v3.1 8.2) 未認証の攻撃者が偽のトークンでMCPセッションを確立できます。CISAが悪用確認済みリストに追加しました。 対処: 1.84.0以降へ更新してください。 htt

    @ForsmileDNet

    3 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Alerte CISA : Exploitation active de la faille critique d’authentification LiteLLM CVE-2026-59822. Elle permet à un attaquant non authentifié d’accéder aux outils MCP. #zoneantimalware https://t.co/6OuFiidTeo

    @NicolasCoolman

    3 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ

    @foxbook

    3 Sept 2026

    263 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🔒 #CyberSecurity CVE-2026-59822: BerriAI LiteLLM MCP Authentication Bypass — Detection and Remed… "On September 2, 2026, CISA added CVE-2026-59822 to its Known Exploited…" 🔗 https://t.co/rfAgDBo8Ea #CyberSecurity #ThreatIntel #cve202659822 #critical #cisakev

    @SecurityAr58409

    3 Sept 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CISO Daily Briefing: Wiz honeypot data — AI-infra attacks doubled in 6mo; MCP servers in ~80% of environments, 5% net-exposed; CVE-2026-59822/CVE-2026-42271 chain to CVSS 10 unauth RCE. Unit 42: LLM safety refusal sits in ~50 of 350K neurons, trivially ablated. APT28's HOOKEDGE

    @cloudsa

    31 Aug 2026

    302 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations