LiteLLM Authentication Flaw Let Single-Character Token Unlock AI Gateway Credentials
A critical improper authentication vulnerability (CVE-2026-59822) in LiteLLM, a widely used AI gateway proxy, allowed attackers to bypass security using any bearer token — including a single character like 'x'. The flaw resided in the OAuth2 header handling code, which returned an empty authentication object on validation failure instead of rejecting the request, effectively granting open access. Attackers could exploit this to list and invoke MCP tools, potentially accessing provider API keys, virtual keys, database credentials, and cloud configurations stored centrally in LiteLLM deployments. Two additional vulnerabilities — a command injection flaw (CVE-2026-42271) and a host header bypass (CVE-2026-48710) — could be chained with the authentication bug to achieve fully unauthenticated remote code execution, a chain linked to the Qilin ransomware group. LiteLLM version 1.84.0 addresses CVE-2026-59822, and users are urged to upgrade immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in