THREAT OPS › CVEs › CVE-2026-59822
CVE-2026-59822 — BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
Vulnerability details
- Affected productsLiteLLM
- KEV remediation due2026-09-16
Related reporting
- CISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-59822 — BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerabilitycisa_kev
- [NVD] CVE-2026-59822 (HIGH 8.2) — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced nvd