Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "litellm", "ai", "authentication"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government", "AI"] ยท au_impact: true

CVE-2026-59822

Affected product: BerriAI LiteLLM (improper authentication)

Patched version: Refer to vendor advisory

Active exploitation: Yes โ€” added to CISA KEV catalog on 2026-09-02

Assessment

CISA added this improper-authentication flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog, confirming active exploitation. LiteLLM is a widely used proxy and gateway for LLM APIs, so an authentication failure there can expose AI model endpoints and credentials. Given LiteLLM's role as a trust boundary for AI infrastructure, organisations should patch promptly and audit access to the gateway.