CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability

Summary

BerriAI LiteLLM has an improper authentication vulnerability in its MCP Streamable HTTP endpoint, allowing unauthenticated attackers to create authenticated sessions with any Bearer token. Users are advised to apply vendor-provided mitigations, follow CISA's guidance on prioritizing security updates, and assess their asset's internet exposure.

IFF Assessment

FOE

The vulnerability allows unauthenticated attackers to gain authenticated access, posing a direct threat to the security of systems using BerriAI LiteLLM.

Severity

8.2 High

CISA KEV: Listed as actively exploited. Federal patch due: September 16, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in BerriAI LiteLLM highlights the critical need for robust authentication mechanisms, especially in cloud-native applications and services. Defenders should prioritize patching or mitigating such vulnerabilities promptly, especially those that allow unauthorized access. The potential for exploitation by ransomware, even if unknown, warrants immediate attention.

Read Full Story →