BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
BerriAI LiteLLM, an AI gateway proxy used to route requests to LLM providers, contains a fail-open authentication flaw in its MCP Streamable HTTP endpoint. Any HTTP request carrying an arbitrary Bearer token, including a single character, triggers an OAuth2 passthrough fallback that substitutes an empty authentication object instead of rejecting the request. An unauthenticated attacker who can reach the endpoint gains a fully authenticated MCP session, with access to model enumeration, MCP-connected tools, and any downstream credentials the proxy holds. Versions prior to 1.84.0 are affected.
The flaw is a fail-open authentication logic error in LiteLLM's MCP Streamable HTTP endpoint. When the server receives a Bearer token that fails LiteLLM key validation, an OAuth2 passthrough fallback path is triggered. Rather than returning an authentication failure, this path substitutes an empty UserAPIKeyAuth() object with no restrictions, allowing the request to proceed as if it were authenticated. The weakness spans CWE-287 (improper authentication) and CWE-306 (missing authentication for a critical function): the check exists but resolves to unrestricted access on failure.
An attacker sends a crafted HTTP request to the MCP Streamable HTTP endpoint with a fabricated Authorization header containing any Bearer token value. Wiz Research honeypot telemetry confirmed active exploitation using single-character tokens to reach model enumeration endpoints. Once a session is established, the attacker can access any MCP-exposed tool, enumerate connected model providers, and retrieve downstream credentials such as LLM provider API keys or cloud IAM tokens held by the proxy. The only precondition is network reachability to the endpoint.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If BerriAI LiteLLM runs inside your authorization boundary, CVE-2026-59822 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA's Known Exploited Vulnerabilities (KEV) catalog lists this vulnerability with a remediation deadline of September 16, 2026. An unpatched KEV inside your boundary is an assessor finding: you remediate it, or you formally document a mitigation before your assessor and sponsoring agency raise it.
Knox does not patch BerriAI LiteLLM on your behalf. Under the FedRAMP shared-responsibility model, that remediation belongs to you. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. Applying the patch is your work; maintaining a defensible compliance posture while you do it is not something you have to manage on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a vulnerability like CVE-2026-59822, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-59822 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation is what keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









