Unauthenticated Access Vulnerability in LiteLLM Proxy Server by BerriAI
CVE-2026-59822

8.8HIGH

Key Information:

Vendor

Berriai

Status
Vendor
CVE Published:
8 July 2026

What is CVE-2026-59822?

LiteLLM, developed by BerriAI, is a proxy server that facilitates the usage of LLM APIs in OpenAI format. In versions prior to 1.84.0, a security flaw existed where an unauthenticated attacker could exploit a specially crafted Authorization header. This vulnerability enabled the attacker to bypass key validation, allowing unauthorized access to MCP tooling without a valid LiteLLM key. This issue was resolved in version 1.84.0, and users are encouraged to upgrade to this version to mitigate potential security risks.

Affected Version(s)

litellm < 1.84.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.