CVE-2026-59822: BerriAI LiteLLM
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
- Vendor
- BerriAI
- Product
- LiteLLM
- Vulnerability
- BerriAI LiteLLM Improper Authentication Vulnerability
- Date added
- Sep 2, 2026
- CISA due date (U.S. federal agencies)
- Sep 16, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-287, CWE-306
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02