CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability

criticalknown exploitedCVE-2026-59822
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

CSIRTS triage

What
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint allowing unauthenticated attackers to establish authenticated sessions with arbitrary Bearer tokens.
Who is affected
Deployments of BerriAI LiteLLM exposing the MCP Streamable HTTP endpoint without proper token validation.
Urgency
Critical; actively exploited and bypasses authentication entirely for MCP session establishment.
Action
Update BerriAI LiteLLM to a patched version and implement Bearer token validation in the MCP endpoint.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch LiteLLM

Get an email when a new LiteLLM advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Known Exploited Vulnerabilities (US · database · site)
Severity
critical
Published
2026-09-02
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59822coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Known Exploited Vulnerabilities