LiteLLM Auth Bypass Flaw Exposes AI Gateway Credentials to Unauthenticated Access
A critical authentication bypass vulnerability in LiteLLM's MCP Streamable HTTP endpoint allowed unauthenticated users to access the gateway by sending a forged or invalid Bearer token, which triggered a fallback to an empty authentication object instead of rejecting the request. Because LiteLLM proxies centrally store API keys for multiple AI model providers and broker connections to databases, code repositories, and internal APIs, the flaw gave attackers broad access to whatever resources the gateway was configured to reach. Security researchers from Wiz and Microsoft reported in September 2026 that the vulnerability was chained with two other flaws — CVE-2026-42271 and CVE-2026-48710 — to achieve unauthenticated remote code execution, with the attack chain linked to the Qilin ransomware group. Attackers were also observed recovering the LiteLLM master key directly from process memory and concealing mining binaries within AI-related directories. Operators are advised to upgrade to LiteLLM version 1.84.0 or later, rotate all exposed credentials, and audit the tools and resources their MCP gateway exposes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in