vulnti.work

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

Info Listed in CISA KEV
CVECVE-2026-59822
First seen2026-09-02 19:15 UTC
Disclosed2026-09-02 00:00 UTC
Last updated2026-09-02 19:15 UTC
Channel statusauto

Summary

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • BerriAI:LiteLLM

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_ingest CISA KEV