YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0011

Incident record

CISA puts a LiteLLM authentication bypass on the exploited list and gives agencies two weeks

Severity
Critical
Status
In the wild
Type
Agent Hijack
Target
BerriAI LiteLLM proxy, before 1.84.0
Actor
unknown
CVE
CVE-2026-59822

What happened

CISA added CVE-2026-59822 to its Known Exploited Vulnerabilities catalogue on 2 September 2026, giving federal agencies until 16 September to remediate under Binding Operational Directive 26-04. A fabricated Authorization header triggered an OAuth2 passthrough fallback that replaced failed key validation with an empty credentials object, so the request carried on without a valid key and reached LiteLLM’s MCP tooling.

The KEV listing is the part that separates this from the rest of the month’s advisories: CISA adds a vulnerability there when it has evidence of exploitation, so this is not a proof of concept. NVD scores it 8.2 high under CVSS 3.1 and GitHub 8.8 high under CVSS 4.0. Fixed in LiteLLM 1.84.0. A proxy that fails open on authentication is the worst shape for this kind of flaw, because everything behind it was built on the assumption that the proxy checked. The maintainer advises blocking MCP endpoints until the proxy is updated.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026