Skip to main content
QUIETLYTIC
Vulnerability

BerriAI LiteLLM Authentication Bypass (CVE-2026-59822)

CVE-2026-59822 lets attackers bypass LiteLLM key validation via a fabricated Authorization header, reaching MCP tooling unauthenticated. Added to CISA KEV Sept. 2, 2026.

CVE-2026-59822
Threat Level
HIGH
CVSS
8.2
Status
Active Exploitation
Confidence
Medium
Affected Products
BerriAI LiteLLM (before 1.84.0)

CVE-2026-59822, a CVSS 8.2 authentication-bypass vulnerability in BerriAI’s LiteLLM AI gateway, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. NVD’s vector confirms the flaw is network-exploitable, requires no privileges and no user interaction, with high impact to confidentiality and low impact to integrity.

What the vulnerability does

NVD tracks CVE-2026-59822 under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function). LiteLLM is a proxy server (“AI Gateway”) that lets applications call various LLM APIs through an OpenAI-compatible interface. Per NVD’s description, versions prior to 1.84.0 had an MCP (Model Context Protocol) Streamable HTTP endpoint that allowed an unauthenticated attacker to send a fabricated Authorization header and trigger an OAuth2 passthrough fallback path — when LiteLLM’s own key validation failed, the fallback replaced it with an empty UserAPIKeyAuth() object instead of rejecting the request, letting requests reach MCP tooling without a valid LiteLLM key. The issue is fixed in version 1.84.0.

Why it’s on KEV

CISA’s September 2 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Security vendor Wiz has published research (linked from NVD’s reference data) describing broader honeypot-observed attacks against exposed AI infrastructure, consistent with — though not confirmed by NVD as specifically documenting — this CVE.

What we don’t yet have

CVSS scoring and the vulnerability description trace to NVD alone, with the GitHub security advisory (GHSA-7488-6r32-c95q) as the underlying vendor disclosure. We’re marking confidence medium on severity pending independent corroboration. We don’t have an EPSS score ingested for this CVE, and we don’t have data on how widely MCP-enabled LiteLLM deployments are exposed to the public internet versus internal networks only.

Why this matters

MCP tooling frequently sits adjacent to systems with real operational reach — file access, code execution, or internal APIs a given MCP server exposes to an authenticated LLM client — so an authentication bypass reaching that layer is materially worse than a bypass that only reaches the LLM proxy itself. As AI-gateway software becomes more common in production stacks, this CVE is a concrete instance of a broader pattern: novel AI-infrastructure components inheriting all the authentication-bypass risk of any other network service, without yet having the maturity of hardening that older infrastructure categories have accumulated. Any organization running LiteLLM with MCP tooling enabled should confirm the 1.84.0+ upgrade specifically, not just a general “latest version” update, since the fix is tied to that exact release.

Frequently Asked Questions

What is CVE-2026-59822? A CVSS 8.2 authentication-bypass vulnerability in LiteLLM (before 1.84.0) that lets an unauthenticated attacker use a fabricated Authorization header to reach MCP tooling without a valid API key.

Is CVE-2026-59822 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 2, 2026.

What should LiteLLM operators do? Upgrade to LiteLLM 1.84.0 or later, which fixes the OAuth2 passthrough fallback path described in the vendor’s security advisory (GHSA-7488-6r32-c95q).


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 13, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools