33,000 LiteLLM Gateways Exposed Online After Auth Bypass Flaw CVE-2026-59822
A critical authentication bypass vulnerability, CVE-2026-59822, was discovered in LiteLLM's MCP Streamable HTTP endpoint and patched in version 1.84.0, with CISA adding it to its Known Exploited Vulnerabilities catalog on September 2, 2026. A ZoomEye scan conducted on September 16, 2026 identified 33,005 internet-facing instances fingerprinted as LiteLLM, highlighting the broad exposure of this AI gateway product. The flaw allowed unauthenticated callers to bypass key checks via a fail-open fallback that substituted an empty auth object instead of rejecting invalid requests. Security researchers at Wiz and Microsoft reported in September 2026 that attackers, linked to the Qilin ransomware group, were chaining this vulnerability with other flaws to achieve code execution on AI infrastructure. Because LiteLLM acts as a centralized proxy holding upstream provider API keys and tool access, a single compromised gateway can expose significant credential material and internal resources.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in