A One-Character Bearer Token Was Enough to Break Into LiteLLM’s MCP Gateway
Wiz Research found that a one-character Bearer token ("Bearer a") bypassed authentication in LiteLLM's Model Context Protocol gateway, tracked as CVE-2026-59822, after 90 days of honeypots mimicking AI infrastructure inc…