Security
Loading…

CVE-2026-59822

HIGHCVSS 8.2Known Exploited
Description

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Timeline
Published:July 8th, 2026 8:16 PM
Last modified:September 3rd, 2026 1:05 PM
Added to KEV:September 2nd, 2026
CVSS Scoring

CVSS v3: 8.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Software
From NVD CPE configuration data

Vendors

litellm

Products

litellm
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute