06:08
2026-09-17
pub.towardsai.net
ai-infrastructure
A One-Character Bearer Token Was Enough to Break Into LiteLLMβs MCP Gateway
Wiz Research found that a one-character Bearer token ("Bearer a") bypassed authentication in LiteLLM's Model Context Protocol gateway, tracked as CVE-2026-59822, after 90 days of honeypots mimicking Aβ¦