HomeCVE Intelligence › CVE-2026-59822
CVSS 7.5 HIGH Vulnerability

CVE-2026-59822: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OAuth2 passthrough for upst…

7.5CVSS Score
HIGHSeverity
NOCISA KEV
0.2%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-59822
Vendorpip
Affected Productlitellm
Vulnerability TypeVulnerability
CVSS Score7.5 (HIGH)
EPSS Score0.2% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key validation with an empty UserAPIKeyAuth() object. This allowed requests with a fabricated Authorization header to reach MCP tooling without a valid LiteLLM key. An attacker could use this to list and call configured MCP tools and access connected services exposed through MCP.

Patches The issue is fixed in 1.84.0. We recommend upgrading to 1.84.0 or later.

Workarounds If upgrading is not immediately possible, disable MCP routes or block access to /mcp/ and related MCP endpoints at y

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-59822 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence