
LiteLLM auth bypass chains to root-level RCE and IAM credential theft. CVE-2026-59822 is actively exploited in the wild and now on CISA KEV, present in roughly one-third of cloud environments. Key findings: - CVE-2026-59822 (MCP auth bypass): the MCP auth handler in user_api_key_auth_mcp.py catches 401s from invalid tokens and returns an empty UserAPIKeyAuth() object, granting a fully authenticated session. A single request with "Authorization: Bearer a" is enough. Honeypot data confirmed active exploitation as of 2026-07-07. Fix landed in v1.84.0. - CVE-2026-59821 (post-auth RCE): the guardrail registration endpoint (POST /guardrails) called exec(compile(...)) without stripping __builtins__ or running the forbidden-patterns check, giving submitted Python the full standard library. Code executed at registration time, not inference time. Fixed in v1.82.0 with sandbox enforcement and PROXY_ADMIN gating. - 9.6% of 3,074 scanned public instances accepted the default master key (sk-1234) or required no auth. Pre-patch, no-auth deployments granted PROXY_ADMIN to every request by default. Chaining default key plus CVE-2026-59821 (pre-v1.82.0) yields pre-auth root in one request. - Pass-through endpoints proxy requests to arbitrary URLs with no validation, including AWS IMDS. The x-pass- header prefix strips and forwards headers to the target, defeating IMDSv2 protections and enabling IAM credential exfiltration post-auth. #DFIR_Radar
Post summary
The piece reports that CVE-2026-59822 is being actively exploited, provides detailed exploitation steps for auth bypass and RCE, and notes patches that have been released.


