Improper access control in LiteLLM - CVE-2026-59822
Published: July 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to access connected services exposed through MCP.
The vulnerability exists due to improper access control in the MCP Streamable HTTP endpoint when handling requests with a fabricated Authorization header during OAuth2 passthrough fallback. A remote attacker can send a request with an arbitrary bearer token to access connected services exposed through MCP.
This issue can allow listing and calling configured MCP tools.