LiteLLM MCP CVE-2026-59822 enters KEV: fabricated bearer tokens can reach connected tools
Published 09 Sep 2026 · Severity: high
CISA added LiteLLM CVE-2026-59822 to KEV on 2 September 2026. Versions before 1.84.0 can accept a fabricated Bearer token at the MCP Streamable HTTP endpoint, allowing unauthenticated access to configured MCP tools and connected services. Upgrade to 1.84.0 or later, or block MCP routes until the fixed version is verified.