← All Advisories

BerriAI LiteLLM's Improper Authentication Allows Unauthenticated Attackers to Access the AI Model Gateway and Interact with Configured LLM Endpoints Without Credentials

Last refreshed2026-09-27

Status: KEV  |  Advisory ID: CVE-2026-59822

Key Details

CVECVE-2026-59822
Vulnerability NameBerriAI LiteLLM Improper Authentication Vulnerability
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-18
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productsBerriAI LiteLLM and litellm LiteLLM
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02.
Exploitation prediction (EPSS)0.84% probability of exploitation in the next 30 days (56% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BerriAILiteLLM
litellmLiteLLM
SubsystemsGeneral OT
SectorsMultiple

What to Know

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

What to Do

Monitor BerriAI's and litellm's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-59822
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-59822
Vendor advisoryhttps://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q

KEV Required Action

FieldValue
KEV Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Date Added to KEV2026-09-02