• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-59822: pre-authentication bypass in BerriAI LiteLLM

Remote attackers can gain unauthorised access to BerriAI LiteLLM and make requests to its MCP tooling by exploiting an authentication fallback in the MCP Streamable HTTP endpoint. CVE-2026-59822 impacts LiteLLM releases before 1.84.0. An attacker with network reach to the endpoint can supply a manipulated Authorization header that triggers the fallback path, causing the server to accept requests without a valid LiteLLM key.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.2HIGH
EPSS
0.00836
CWE
CWE-287
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

High priority: CISA placed this flaw on the Known Exploited Vulnerabilities list with a remediation deadline and public exploit code exists — immediately reduce exposure and apply vendor guidance.

What is CVE-2026-59822?

Remote attackers can gain unauthorised access to BerriAI LiteLLM and make requests to its MCP tooling by exploiting an authentication fallback in the MCP Streamable HTTP endpoint. CVE-2026-59822 impacts LiteLLM releases before 1.84.0. An attacker with network reach to the endpoint can supply a manipulated Authorization header that triggers the fallback path, causing the server to accept requests without a valid LiteLLM key. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Which versions of BerriAI LiteLLM are affected?

BRANCHAFFECTEDFIXED
litellm< 1.84.0

Is CVE-2026-59822 being exploited?

CISA added CVE-2026-59822 to the Known Exploited Vulnerabilities catalog on 2026-09-02, with a required remediation date of 2026-09-16; public exploit code is available.

How to fix CVE-2026-59822

  1. Block or restrict inbound network access to the LiteLLM MCP Streamable HTTP endpoint from untrusted networks.
  2. Implement vendor-recommended configuration changes or mitigations as soon as BerriAI publishes them.
  3. Inspect access and application logs for unexpected MCP sessions and suspicious Authorization header patterns.
  4. If mitigations are not available, remove or isolate exposed instances per CISA guidance until a fix is provided.

Frequently asked questions

Is CVE-2026-59822 being actively exploited?

CISA added CVE-2026-59822 to its Known Exploited Vulnerabilities catalog on 2026-09-02 and set a remediation due date of 2026-09-16; public exploit code is also available.

Which LiteLLM versions are affected by CVE-2026-59822?

LiteLLM versions earlier than 1.84.0 are reported as affected by CVE-2026-59822.

Is there a patch for CVE-2026-59822?

There is no patch available as of 2026-09-29; follow vendor guidance and apply mitigations until an official fix is provided.

Does CVE-2026-59822 require authentication?

No — the vulnerability allows an unauthenticated attacker to trigger an authentication fallback and establish an MCP session.

References