security1 publisher
CVE-2026-59822 lets any Bearer token open an MCP session on LiteLLM gateways
LiteLLM's MCP endpoint accepts an arbitrary Bearer token as a valid session, and CISA has already added the bypass to its exploited-vulnerability catalog after Wiz watched attackers use it against honeypots.
Publishers:wiz.io
Reality
- Evidence62
- Adoption68
- Hype gap+15
- Incentives70
- Confidence58