CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability
Summary
BerriAI LiteLLM has an improper authentication vulnerability in its MCP Streamable HTTP endpoint, allowing unauthenticated attackers to create authenticated sessions with any Bearer token. Users are advised to apply vendor-provided mitigations, follow CISA's guidance on prioritizing security updates, and assess their asset's internet exposure.
IFF Assessment
The vulnerability allows unauthenticated attackers to gain authenticated access, posing a direct threat to the security of systems using BerriAI LiteLLM.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 16, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in BerriAI LiteLLM highlights the critical need for robust authentication mechanisms, especially in cloud-native applications and services. Defenders should prioritize patching or mitigating such vulnerabilities promptly, especially those that allow unauthorized access. The potential for exploitation by ransomware, even if unknown, warrants immediate attention.