Key Facts

Wiz Research reports that 9.6% of 3,074 sampled internet-facing LiteLLM instances accepted the default master key or required no authentication. Wiz says it found an MCP authentication bypass (CVE-2026-59822) and observed it being exploited in its honeypot infrastructure.

Technical Details

Wiz says arbitrary Bearer tokens can create authenticated MCP sessions through the affected authentication path. It also describes a post-authentication root-level code-execution issue in custom code guardrails (CVE-2026-59821) and a post-authentication cloud-credential theft path through pass-through endpoints without URL validation.

Impact & Mitigation

Replace default master keys, require authentication, and apply available LiteLLM patches. Wiz says the pass-through endpoint behavior was not considered a vulnerability, so also restrict outbound access, limit workload IAM permissions, and review exposure of connected MCP tools and cloud credentials.

Sources

By Allan