XT.PT AI infrastructure → This story
Filed

Updated 07:23
Reporting
Prelo
Verified by Roger Morais
4 min · 652 words
News AI infrastructure

The fallback that opened LiteLLM's MCP door

Patched in May, disclosed in June, exploited in honeypots by August, and now on a federal deadline of September 16.

Filed10 Sep 2026, 10:30 UTC Length4 min · 652 words ReportingPrelo
python code

On September 2, CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog. One of them is the first MCP-specific bug the catalog has carried: "CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability."

LiteLLM is the open-source proxy many teams put in front of model APIs to unify keys, budgets and routing. Since it grew an MCP gateway, it also fronts tools.

What the bug is

The GitHub advisory, GHSA-7488-6r32-c95q, is titled "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback." Its summary: the MCP Streamable HTTP endpoint allowed "an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token." The mechanism is a fallback meant for passing OAuth2 tokens through to upstream MCP servers, which could "replace failed LiteLLM key validation with an empty UserAPIKeyAuth() object."

An empty auth object is not a rejected request. It is a request with no owner and no restrictions. The advisory states the impact plainly: an attacker could "list and call configured MCP tools and access connected services exposed through MCP."

Affected versions are everything before 1.84.0. Severity is High, with a CVSS v4 score of 8.8.

What exploitation looked like

Wiz's 90-day honeypot report, published August 27, describes the same fallback from the wire: when authentication failed, "the server returns an empty UserAPIKeyAuth() object with no restrictions." The observed requests carried a single-character token, Authorization: Bearer x, and used the resulting session to probe model enumeration endpoints. Wiz also saw a second LiteLLM MCP weakness in use, command injection through test endpoints, where attackers "submitted Python scripts within fake MCP configurations to download and execute cryptominers."

CISA's catalog entry records what it always does and nothing more: the vulnerability "could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token," and "knownRansomwareCampaignUse" is "Unknown."

The timeline is the story

  • May 14: LiteLLM v1.84.0 ships with the fix in a changelog line that reads "fix(mcp): tighten public-route detection and OAuth2 fallback gating" (PR #26463). The release warns of breaking changes; it does not say "security."
  • June 30: GitHub publishes the advisory with the CVE.
  • August 27: Wiz reports exploitation in honeypots.
  • September 2: CISA adds it to KEV.
  • September 16: the KEV due date for federal civilian agencies.

Anyone who upgrades LiteLLM only when a release says "security fix" had a window of about seven weeks between the patch and the advisory, and eleven between the patch and the honeypot evidence.

Remediation

Upgrade to 1.84.0 or later. Where that is not immediate, the advisory's workaround is to "disable MCP routes or block access to /mcp/ and related MCP endpoints at your reverse proxy or API gateway." That is a one-line location deny on nginx, and it costs nothing if you do not use the MCP gateway, which many LiteLLM deployments do not. After patching, review what tools the gateway exposes, because an empty identity reached all of them.

The KEV entry's "requiredAction" ties remediation to "CISA's BOD 26-04 Prioritizing Security Updates Based on Risk" and its "Forensics Triage Requirements," and says to "discontinue use of the product if mitigations are unavailable." The directive binds only federal civilian agencies, and CISA's alert repeats its usual line: "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."

One more entry from the same batch deserves a look from Python shops: CVE-2026-48710 in Starlette, the ASGI toolkit under FastAPI, added the same day with the same September 16 due date. CISA's description says it "could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL's path."

Primary sources: CISA alert, September 2, 2026, CISA KEV catalog feed, GHSA-7488-6r32-c95q, LiteLLM v1.84.0 release, Wiz: Attacks on AI Infrastructure, 90-Day Honeypot Telemetry, read 2026-09-08.

Corrections and source documents: contact the desk
Read next →
Read next
Edge devices · 4 min

NetScaler 14.1-73.37 fixes eight CVEs, and the exploited CVE-2026-88771 needs no special configuration

WordPress · 4 min

WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days