Threat+Constellation
Live UTC
← Incidents
INCIDENT 406Exploited vulnerabilityLOW / UNDER REVIEWSourcedNew today

CVE-2026-59822 added to CISA KEV: BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Product: BerriAI LiteLLM. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitiga…

Last evidence update
02 SEP 2026 · 00:00 UTC
Source count
1
Status
reported
CVE-2026-59822
Observation history

How this record has evolved as evidence accumulated.

03 SEP · 05:22 UTC
Initial report
Evidence
Related incidents