Tools AI Risk Radar ai-incident-0011
Incident record
CISA puts a LiteLLM authentication bypass on the exploited list and gives agencies two weeks
- Severity
- Critical
- Status
- In the wild
- Type
- Agent Hijack
- Target
- BerriAI LiteLLM proxy, before 1.84.0
- Actor
- unknown
- CVE
- CVE-2026-59822
What happened
CISA added CVE-2026-59822 to its Known Exploited Vulnerabilities catalogue on 2 September 2026, giving federal agencies until 16 September to remediate under Binding Operational Directive 26-04. A fabricated Authorization header triggered an OAuth2 passthrough fallback that replaced failed key validation with an empty credentials object, so the request carried on without a valid key and reached LiteLLM’s MCP tooling.
The KEV listing is the part that separates this from the rest of the month’s advisories: CISA adds a vulnerability there when it has evidence of exploitation, so this is not a proof of concept. NVD scores it 8.2 high under CVSS 3.1 and GitHub 8.8 high under CVSS 4.0. Fixed in LiteLLM 1.84.0. A proxy that fails open on authentication is the worst shape for this kind of flaw, because everything behind it was built on the assumption that the proxy checked. The maintainer advises blocking MCP endpoints until the proxy is updated.
Sources
- CISA Known Exploited Vulnerabilities cataloguewww.cisa.gov/sites/default/files/feeds/known_exploited_vulne…
- GitHub Security Advisory GHSA-7488-6r32-c95qgithub.com/BerriAI/litellm/security/advisories/GHSA-7488-6r3…
- NVD record, CVE-2026-59822nvd.nist.gov/vuln/detail/CVE-2026-59822
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026