First published · Last updated
CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability
A vulnerability in BerriAI LiteLLM's MCP Streamable HTTP endpoint can allow an unauthenticated actor to establish an authenticated MCP session using an arbitrary Bearer token. The advisory directs applying vendor mitigations and following CISA BOD 26-04 and forensics triage guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 2/10
- Global importance
- 4/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
If exploited, attackers could obtain unauthorized authenticated sessions on systems using the affected product.

