forkast.news Critical LiteLLM Authentication Bypass Vulnerability Discovered
Article Content
- •CVE-2026-59822 allows unauthenticated access to LiteLLM MCP tools.
- •CISA added the vulnerability to its KEV catalog on September 2, 2026.
- •No public exploitation or proof-of-concept code has been reported yet.
A critical authentication vulnerability, CVE-2026-59822, was identified in LiteLLM, affecting versions prior to 1.84.0. This flaw allows unauthenticated attackers to bypass security checks through an OAuth2 passthrough fallback mechanism, enabling them to list and execute configured Model Context Protocol (MCP) tools. The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. Organizations are expected to remediate the issue within 2-3 weeks or disable the /mcp/ endpoints. Currently, there is no evidence of public exploitation or functional proof-of-concept scripts. The vulnerability carries a CVSS score of 8.8, indicating high severity due to its ease of exploitation and potential impact on connected services.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-59822 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
AI-Driven Cyber Attacks Targeting Critical Infrastructure and Data Security A recent wave of cyber attacks orchestrated by AI agents has exploited vulnerabilities in systems like PaperCut, leading to significant breaches across various sectors including education and healthcare. The attacks utilized CVE-2026-81578 and CVE-2026-82078 to achieve remote code execution without authentication…