The AI Gateway Is Now a Credential Hub: What the LiteLLM MCP Authentication Bypass Means for Self-Hosted LLM Infrastructure
In LiteLLM before version 1.84.0, vulnerability CVE-2026-59822 (CVSS 8.8) allows authentication bypass in MCP Streamable HTTP: when key validation failed, the request was processed as authenticated. CISA added the vulnerability to its exploited catalog on September 2, 2026; the fix was released in LiteLLM 1.84.0.
- CVE-2026-59822: CVSS 8.8, CWE-287, fixed in LiteLLM 1.84.0
- A forged Authorization header granted access to the gateway's MCP tools
- CISA added the vulnerability to its exploited catalog on September 2, 2026
- Wiz and Microsoft linked the attacks to an RCE chain and the Qilin group
Read next
Security