Status: KEV
| Advisory ID: CVE-2026-59822
Key Details
| CVE | CVE-2026-59822 |
| Vulnerability Name | BerriAI LiteLLM Improper Authentication Vulnerability |
| CVSS Score / Version | 8.2 (High) / CVSS v3.1 |
| Updated | 2026-09-18 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none. |
| Affected products | BerriAI LiteLLM and litellm LiteLLM |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02. |
| Exploitation prediction (EPSS) | 0.84% probability of exploitation in the next 30 days (56% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
What to Do
Monitor BerriAI's and litellm's web pages for any future patch releases. See vendor advisory link below.
References
KEV Required Action