{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/litellm--1.84.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:litellm:litellm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-59822"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LiteLLM (\u003c 1.84.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","api-security","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["BerriAI"],"content_html":"\u003cp\u003eA critical authentication bypass vulnerability, tracked as CVE-2026-59822, has been discovered in LiteLLM's MCP (Microservice Communication Protocol) Streamable HTTP endpoint. This flaw, present in versions prior to 1.84.0, allows an unauthenticated attacker to establish an authenticated MCP session by exploiting a specific fallback mechanism in the OAuth2 passthrough handler. When a legitimate LiteLLM key validation fails, the vulnerable system inappropriately replaces the authentication object with an empty one. This behavior permits requests with any fabricated \u003ccode\u003eAuthorization: Bearer\u003c/code\u003e token to be processed as authenticated, thereby granting unauthorized access to internal MCP tooling and connected services. The vulnerability puts organizations using LiteLLM at risk of unauthorized data access, command execution via MCP tools, and potential broader system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eReconnaissance\u003c/strong\u003e: An attacker identifies publicly exposed LiteLLM instances that utilize the MCP Streamable HTTP endpoint.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eVulnerability Identification\u003c/strong\u003e: The attacker determines that the LiteLLM instance is running a version prior to 1.84.0, confirming its susceptibility to CVE-2026-59822.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCraft Malicious Request\u003c/strong\u003e: The attacker constructs an HTTP request targeting a sensitive MCP endpoint (e.g., \u003ccode\u003e/mcp/call_tool\u003c/code\u003e, \u003ccode\u003e/mcp/list_tools\u003c/code\u003e) and embeds an arbitrary \u003ccode\u003eAuthorization: Bearer \u0026lt;token\u0026gt;\u003c/code\u003e header. The content of the token does not need to be valid or formatted specifically.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSend Request\u003c/strong\u003e: The crafted HTTP request is sent to the vulnerable LiteLLM server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBypass Authentication\u003c/strong\u003e: Upon receiving the request, the LiteLLM server's MCP auth handler attempts key validation. Due to the vulnerability's fallback path, failed validation results in an empty \u003ccode\u003eUserAPIKeyAuth()\u003c/code\u003e object, effectively bypassing the intended authentication check.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAccess MCP Tools\u003c/strong\u003e: The LiteLLM server processes the request as if it originated from an authenticated user, granting the attacker the ability to list available MCP tools and execute arbitrary calls through them.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAccess Connected Services\u003c/strong\u003e: Leveraging the compromised MCP session, the attacker interacts with any services connected and exposed via MCP, potentially leading to data exfiltration, system manipulation, or further lateral movement within the network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-59822 allows an unauthenticated attacker to gain unauthorized access to LiteLLM's internal MCP tooling and any services integrated with or exposed through it. This can lead to significant data breaches, unauthorized data manipulation, or even remote code execution if the MCP tools provide such capabilities. The number of potentially affected organizations is any LiteLLM user running a vulnerable version with MCP endpoints exposed. While specific victim counts are not available, the nature of the bypass indicates a critical risk for systems handling sensitive data or connected to critical infrastructure through LiteLLM.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eUpgrade LiteLLM\u003c/strong\u003e: Immediately upgrade all LiteLLM instances to version \u003ccode\u003e1.84.0\u003c/code\u003e or later to patch CVE-2026-59822.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNetwork Segmentation/Blocking\u003c/strong\u003e: If immediate upgrading is not feasible, disable MCP routes or block access to \u003ccode\u003e/mcp/\u003c/code\u003e and any related MCP endpoints at your reverse proxy or API gateway.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview Access Logs\u003c/strong\u003e: Scrutinize web server or API gateway access logs for unusual requests to \u003ccode\u003e/mcp/\u003c/code\u003e endpoints, especially those with \u003ccode\u003eAuthorization: Bearer\u003c/code\u003e headers, as these might indicate attempted exploitation of CVE-2026-59822.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T22:39:57Z","date_published":"2026-07-22T22:39:57Z","id":"https://feed.craftedsignal.io/briefs/2026-07-litellm-mcp-auth-bypass/","summary":"An authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.","title":"LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback","url":"https://feed.craftedsignal.io/briefs/2026-07-litellm-mcp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - LiteLLM (\u003c 1.84.0)","version":"https://jsonfeed.org/version/1.1"}