Skip to content
Critical LiteLLM Authentication Bypass Vulnerability Discovered

Critical LiteLLM Authentication Bypass Vulnerability Discovered

First seen 19 Sep 2026, 15:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 14:21 UTC
  • CVE-2026-59822 allows unauthenticated access to LiteLLM MCP tools.
  • CISA added the vulnerability to its KEV catalog on September 2, 2026.
  • No public exploitation or proof-of-concept code has been reported yet.

A critical authentication vulnerability, CVE-2026-59822, was identified in LiteLLM, affecting versions prior to 1.84.0. This flaw allows unauthenticated attackers to bypass security checks through an OAuth2 passthrough fallback mechanism, enabling them to list and execute configured Model Context Protocol (MCP) tools. The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. Organizations are expected to remediate the issue within 2-3 weeks or disable the /mcp/ endpoints. Currently, there is no evidence of public exploitation or functional proof-of-concept scripts. The vulnerability carries a CVSS score of 8.8, indicating high severity due to its ease of exploitation and potential impact on connected services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-08
CVE-2026-59822 published
LiteLLM's critical authentication flaw was officially disclosed, highlighting significant security risks.
Cryptorank
2026-09-02
CVE-2026-59822 added to CISA KEV
CISA included the LiteLLM vulnerability in its Known Exploited Vulnerabilities catalog, marking a significant alert for federal agencies.
Cryptorank
2026-09-03
First public PoC released
The first proof-of-concept exploit for CVE-2026-59822 was made public, raising concerns about potential exploitation.
Forkast

More articles in this cluster (3)

Following this threat?

Track CVE-2026-59822 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed