← Back to CVE List
Vulnerability Intelligence Report
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

CVE-2026-59822

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

CISA KEV SSVC: Active Exploitation Automatable Authentication Bypass
CVSS Base Score
8.8
HIGH
EPSS Probability:0.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-287 ↗CWE-287: Improper Authentication
CWE-306 ↗CWE-306: Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
BerriAI litellm < 1.84.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.516%
Vulnerability Class
Authentication Bypass

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-07T15:00:50
Published2026-07-08T19:32:18
Last Updated2026-09-03T03:56:05

LINK COPIED TO CLIPBOARD