2 hrs ago
CISA Flags Actively Exploited Authentication Flaw in LiteLLM
The United States added a serious LiteLLM software bug to its list of exploited vulnerabilities.
LiteLLM helps applications connect to different artificial-intelligence model providers.
The bug can let someone bypass a login check.
The vulnerability is called CVE-2026-59822 and has a severity score of 8.8.
LiteLLM may hold valuable API keys and handle sensitive information sent to and received from AI models.
This means an attacker could potentially reach both credentials and private AI conversations.
Organizations using LiteLLM should update it and replace the API keys it stored.
They should also check what other AI software is connected to their systems.
The Cybersecurity and Infrastructure Security Agency added seven vulnerabilities to its Known Exploited Vulnerabilities catalogue.
CVE-2026-59822 is an authentication bypass in LiteLLM’s MCP Streamable HTTP endpoint.
The vulnerability has a CVSS score of 8.8 and is reportedly being exploited in the wild.
LiteLLM can store provider API keys and process sensitive prompts, completions, documents, records, and source code.
Organizations are advised to patch LiteLLM, rotate provider API keys, and inventory AI infrastructure around their applications.
- Who
- The Cybersecurity and Infrastructure Security Agency, organizations using LiteLLM, and unspecified attackers reportedly exploiting the vulnerability.
- What
- CVE-2026-59822, an authentication bypass in LiteLLM’s MCP Streamable HTTP endpoint, was added to the Known Exploited Vulnerabilities catalogue.
- Where
- The vulnerability affects LiteLLM deployments and was added to the United States’ Known Exploited Vulnerabilities catalogue.
- When
- Why
- It was listed because reliable evidence indicates active exploitation in the wild.
Key facts
- Vulnerability
- CVE-2026-59822
- Affected software
- LiteLLM
- Affected component
- MCP Streamable HTTP endpoint
- Vulnerability type
- Authentication bypass
- CVSS score
- 8.8
- Catalogue
- Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalogue
- Recommended response
- Patch LiteLLM and rotate every provider API key it held









