Threat · curated 25 Jul 2026

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | GitLab Advisory Database (GLAD)

Coverage timeline

25 Jul 2026gitlab.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

LiteLLM is a widely used LLM proxy/gateway, and this flaw lets attackers reach MCP tooling and downstream connected services without a valid key, exposing agentic integrations to unauthenticated abuse.

CVE-2026-59822 is an authentication bypass in LiteLLM's MCP Streamable HTTP endpoint, where the OAuth2 passthrough fallback path replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object. An unauthenticated attacker could supply an arbitrary/fabricated Bearer token to establish an authenticated MCP session, then list and call configured MCP tools and access connected services. The issue is fixed in LiteLLM v1.84.0.