CVE-2026-59822
published 2026-07-08CVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an…
PriorityP183high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-16
Exploited in the wild
EPSS
0.87%
56.7th percentile
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| berriai | litellm | < 1.84.0 | 1.84.0 |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| litellm | litellm | < 1.84.0 | 1.84.0 |
| litellm | litellm | >= 0 < 1.84.0 | 1.84.0 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck8.2HIGH
cisa8.2HIGH
vendor_redhat8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
BerriAI litellm up to 1.83.x Streamable HTTP Endpoint UserAPIKeyAuth Authorization improper authorization (EUVD-2026-42359 / WID-SEC-2026-2263)
vuldb·2026-07-23·CVSS 8.2
CVE-2026-59822 [HIGH] BerriAI litellm up to 1.83.x Streamable HTTP Endpoint UserAPIKeyAuth Authorization improper authorization (EUVD-2026-42359 / WID-SEC-2026-2263)
A vulnerability marked as critical has been reported in BerriAI litellm up to 1.83.x. Impacted is the function UserAPIKeyAuth of the component Streamable HTTP Endpoint. This manipulation of the argument Authorization causes improper authorization.
This vulnerability is registered as CVE-2026-59822. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
ghsa·2026-07-22
CVE-2026-59822 [HIGH] CWE-287 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
### Impact
LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key validation with an empty `UserAPIKeyAuth()` object. This allowed requests with a fabricated `Authorization` header to reach MCP tooling without a valid LiteLLM key.
An attacker could use this to list and call configured MCP tools and access connected services exposed through MCP.
### Patches
The issue is fixed in `1.84.0`.
We recommend upgrading to `1.84.0` or later.
### Workarounds
If upgrading is not immediately possible,
VulnCheck
litellm litellm Improper Authentication
vulncheck·2026·CVSS 8.2
CVE-2026-59822 [HIGH] litellm litellm Improper Authentication
litellm litellm Improper Authentication
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Affected: litellm litellm
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.linkedin.com/posts/yaarashriki_cve-2026-59821-cve-2026-59822-i-found-activity-748
VulnCheck
litellm litellm Improper Control of Generation of Code ('Code Injection')
vulncheck·2026·CVSS 7.2
CVE-2026-59821 [HIGH] litellm litellm Improper Control of Generation of Code ('Code Injection')
litellm litellm Improper Control of Generation of Code ('Code Injection')
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by the test endpoint, allowing a privileged user with access to create or update guardrails to submit custom Python code that executed in the LiteLLM proxy environment and could expose secrets available to the process. This issue is fixed in version 1.82.0-stable.
Affected: litellm litellm
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.linked
CISA
BerriAI LiteLLM Improper Authentication Vulnerability
cisa·2026-09-02·CVSS 8.2
CVE-2026-59822 [HIGH] CWE-287 BerriAI LiteLLM Improper Authentication Vulnerability
Vulnerability: BerriAI LiteLLM Improper Authentication Vulnerability
Affected: BerriAI LiteLLM
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26
Red Hat
litellm: LiteLLM: Unauthorized access due to authentication bypass
vendor_redhat·2026-07-08·CVSS 8.2
CVE-2026-59822 [HIGH] CWE-303 litellm: LiteLLM: Unauthorized access due to authentication bypass
litellm: LiteLLM: Unauthorized access due to authentication bypass
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
A flaw was found in LiteLLM, a proxy server designed for Large Language Model (LLM) APIs. An unauthenticated attacker could exploit a vulnerability in the MCP Streamable HTTP endpoint. By using a fabricated Authorization header, the attacker could bypass the standard key val
No detection rules found.
No public exploits indexed.
Wiz
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
blogs_wiz·2026-09-09·CVSS 7.2
CVE-2026-59822 [HIGH] Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication at all. We found this while scanning roughly 3,000 internet-facing deployments of the most popular open-source LLM gateway. The usual concern with that kind of exposure is LLMjacking -someone using the credentials to run API calls on your bill - however, we wanted to check whether an attacker could do worse than that: could they achieve code execution on the host? Furthermore, could they exploit this to compromise the wider environment?
We decided to use Claude Code to work through LiteLLM's codebase, looking for features that accept user-controlled input and pass it to an execution context. We found multiple issues, as detailed below.
Key findings:
MCP authentication bypass via
Hackernews
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
blogs_hackernews·2026-09-03·CVSS 6.5
CVE-2026-83548 [MEDIUM] CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549 (CVSS score: 7.8) - A post-authen
Wiz
Inside 90 days of attacks on AI infrastructure
blogs_wiz·2026-08-27
CVE-2026-59822 Inside 90 days of attacks on AI infrastructure
Wiz Threat Research operates honeypots across AI and ML services including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, and others. Over 90 days of telemetry, we observed sustained attack activity against AI infrastructure, with tooling adapted to the specific internals of each service. We’re sharing our findings with the community so that organizations can defend themselves against the techniques we’ve observed so far.
The findings below are organized around three attack patterns:
Exploiting Internet-facing MCP servers for remote code execution
Blind prompt injection against AI agent frameworks
AI-native post-exploitation, with tooling adapted specifically to AI infrastructure internals
## Why AI infrastructure matters as a cloud attack surface
Wiz’s State of AI in the C
Bugzilla
CVE-2026-59822 litellm: LiteLLM: Unauthorized access due to authentication bypass
bugzilla·2026-07-08·CVSS 8.2
CVE-2026-59822 [HIGH] CVE-2026-59822 litellm: LiteLLM: Unauthorized access due to authentication bypass
CVE-2026-59822 litellm: LiteLLM: Unauthorized access due to authentication bypass
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2chttps://github.com/BerriAI/litellm/pull/26463https://github.com/BerriAI/litellm/releases/tag/v1.84.0https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95qhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59822https://www.wiz.io/blog/ai-infrastructure-honeypot
2026-07-08
Published
2026-09-02
Added to CISA KEV
Exploited in the wild