Cybersecurity Research

Critical Flaws in Popular AI Gateway LiteLLM Let Attackers Hijack Servers and Steal Cloud Credentials

Wiz Research · 10 Sept 2026
Key Takeaway If your business uses LiteLLM or similar AI gateways, immediately change any default credentials, enforce strong authentication, and apply the latest security patches without delay.

Researchers examining LiteLLM, a popular open-source gateway that businesses use to manage and route traffic to AI providers like OpenAI, Anthropic and Azure, discovered that nearly 1 in 10 of roughly 3,000 publicly accessible instances scanned either used the default master key or had no authentication at all. This exposure means anyone could potentially access these systems without valid credentials.

The research uncovered multiple serious issues, including an authentication bypass in LiteLLM's MCP endpoint (CVE-2026-59822) that lets an attacker use any bearer token to create a valid session, and a post-authentication flaw (CVE-2026-59821) that can lead to full remote code execution with root-level access via the platform's custom code guardrails feature. Where instances had no authentication configured, all users were granted full admin access by default. Researchers also identified a technique involving LiteLLM's pass-through endpoint that could allow theft of cloud credentials once inside the system; this was not classed as a formal vulnerability and remains unpatched, though it typically requires prior access to exploit.

All the confirmed vulnerabilities have been disclosed to LiteLLM's developers, and patches are now available. CVE-2026-59822 has been added to CISA's Known Exploited Vulnerabilities catalog after being observed being actively exploited in the wild.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Wiz Research. We link back to every original so you can read it yourself.