LiteLLM CVE-2026-59822: First MCP Flaw on CISA’s Exploit List — Patch Now CISA added CVE-2026-59822, an authentication bypass in LiteLLM's MCP Streamable HTTP endpoint rated CVSS 8.8, to its Known Exploited Vulnerabilities catalog on September 2 — the first MCP-specific flaw ever listed there. The flaw lets any fabricated Bearer token, even a single character, create an authenticated MCP session, exposing upstream LLM API keys and backend credentials; Wiz honeypots logged exploitation starting July 7. LiteLLM patched the issue in v1.84.0 on May 14, 2026, and operators running MCP routes on earlier versions should upgrade (current release v1.103.0 as of September 27) and rotate credentials. On September 2, CISA added CVE-2026-59822 to its Known Exploited Vulnerabilities catalog — the first MCP-specific flaw to land there. If you run LiteLLM with MCP routes enabled and you are not on v1.84.0 or later, you have an unauthenticated attacker with access to your AI gateway right now. What the Vulnerability Is CVE-2026-59822 is an authentication bypass in LiteLLM’s MCP Streamable HTTP endpoint. CVSS 8.8. Unauthenticated. Remote. No user interaction required. The root cause is a flawed OAuth2 passthrough fallback. LiteLLM’s MCP auth handler supports OAuth2 passthrough to upstream servers. When API key validation fails, the intended behavior is to reject the request. What actually happens: the handler substitutes an empty UserAPIKeyAuth object and lets the request proceed. Any fabricated Bearer token — even a single character — produces what the system treats as an authenticated MCP session. The patch exists. LiteLLM shipped v1.84.0 on May 14, 2026. The problem is that self-hosted AI gateway deployments tend to lag on updates, and CISA’s KEV listing https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog confirms attackers found that out before many operators did. What Attackers Get When They Get In Your LiteLLM gateway is not just a proxy. It is the control plane for your AI stack — the thing that holds your OpenAI key, your Anthropic key, your Cohere key, your backend service credentials. CVE-2026-59822 hands all of that to whoever wants it. Once through the auth bypass, an attacker can enumerate and call any configured MCP tools, pull upstream LLM API keys, access model outputs, grab backend credentials, and move laterally into everything the gateway touches. Wiz’s honeypot infrastructure https://www.wiz.io/blog/ai-infrastructure-honeypot logged exploitation beginning July 7, weeks before the CISA listing. Single-character tokens were used to probe model enumeration endpoints. Admin token minting and credential enumeration followed. This is not theoretical. The attack pattern is confirmed in the wild. Why This One Is Different LiteLLM has had CVEs before. CVE-2026-59822 carries different weight because of where it landed. This is the first MCP vulnerability ever added to CISA’s Known Exploited Vulnerabilities catalog. Through July 2026, 14 CVEs had been assigned to MCP implementations https://www.practical-devsecops.com/mcp-security-statistics-2026-report/ . None made it to the KEV list until now. That is the federal government formally acknowledging that MCP is enterprise attack surface, not developer tooling. Security researchers have drawn the comparison to early REST API auth vulnerabilities of the mid-2010s, when authentication logic for API gateways was still maturing. The difference is that the blast radius is larger. MCP sessions are designed to grant action , not just data access. A compromised REST endpoint leaks data. A compromised MCP session executes. How to Fix It Upgrade to LiteLLM v1.84.0 or later. As of September 27, the current release is v1.103.0. Check your version and upgrade: Check your current version pip show litellm | grep Version Upgrade to latest pip install --upgrade litellm Or pin to minimum safe version pip install "litellm =1.84.0" If you cannot upgrade immediately, the interim workaround is to disable MCP routes entirely or block access to /mcp/ endpoints at the network layer. See the v1.84.0 release notes https://docs.litellm.ai/release notes/v1.84.0/v1-84-0 for the full change details. Either way, rotate your credentials. Any LLM provider API keys, backend service tokens, or secrets your LiteLLM instance has access to should be treated as potentially compromised if you were running a vulnerable version with MCP enabled. The honeypot data shows quiet enumeration, not loud alerts. Do not assume you were not targeted just because nothing looked unusual. The Broader Signal Fourteen MCP CVEs in eight months. The first one on the federal exploit catalog. Over 200,000 MCP servers with various exposed vulnerabilities as of July 2026. MCP is becoming the standard interface between AI agents and the rest of your infrastructure. That makes it exactly the kind of target that attracts sustained attention. The authentication model between agents, gateways, and tools https://www.ionix.io/threat-center/cve-2026-59822/ is still maturing — and attackers are doing the research that shows where it is not yet solid. Treat your AI gateway like you treat your API gateway: version it, monitor it, patch it on a schedule, and put it behind authentication you actually verify. CVE-2026-59822 is a reasonable place to start that discipline.