News

LiteLLM MCP auth bypass under active exploit

Wiz Research says CVE-2026-59822, an MCP authentication bypass in BerriAI LiteLLM, is under active exploit. CISA added it to KEV on 2 September 2026 with a federal due date of 16 September. Of 3,074 public instances, 9.6% accepted the default master key or required no auth.

LiteLLM MCP auth bypass under active exploit

Wiz researchers Amitai Cohen and Yaara Shriki, in a 9 September 2026 research blog, say attackers are exploiting an authentication bypass in BerriAI's LiteLLM Model Context Protocol endpoint. CISA added the same bug, CVE-2026-59822, to its Known Exploited Vulnerabilities catalog on 2 September 2026 as "BerriAI LiteLLM Improper Authentication Vulnerability," with a federal remediation due date of 16 September 2026.

This is a vendor research disclosure plus a CISA KEV listing. It is not a LiteLLM company incident blog, and CISA has not published a fuller advisory beyond the catalog entry. Wiz names no victim organizations.

CVE-2026-59822 lets an arbitrary Bearer token create a valid MCP session, including a token as thin as "Bearer a." LiteLLM fixed that path in v1.84.0 on 25 April 2026. Wiz first saw exploitation in its honeypot on 7 July 2026, one day before the CVE was published.

A second bug, CVE-2026-59821, is post-auth root-level remote code execution through custom code guardrails that reached exec and compile. That one was fixed in v1.82.0 on 25 February 2026. After those patches, the RCE path still needs admin rights, or a default or missing master key.

Wiz also says a pass-through endpoint can reach cloud metadata and IAM when that admin (or default) access is available. Wiz treats that feature as intended admin trust, not a separate CVE.

The scan figure the headlines often drop is the default-key rate. Of 3,074 public LiteLLM instances, 9.6% (294) accepted the default master key sk-1234 or required no authentication, and 6.2% (191) had no auth at all. Wiz says LiteLLM is present in about one third of cloud environments in its data. The default key still appears in LiteLLM docs and examples, and the research was presented earlier at DEF CON 34.

Related AI-infrastructure and exploited-bug coverage includes the ChatGPT sandbox cross-account leak, Anthropic's fourth Claude cyber eval breakout, the WeChat WeWorm zero-click worm, and Chrome's exploited V8 type confusion.

If you run LiteLLM, rotate off sk-1234 to a unique master key today, patch to v1.84.0 or later for the MCP bypass (and v1.82.0 or later for the guardrail RCE), audit custom guardrails and pass-through routes, and lock the proxy's IAM to least privilege before the 16 September federal KEV date.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free