Wiz researchers found that 294 of 3,074 internet-facing LiteLLM gateways accepted the documented default administrator key, sk-1234, while 191 had no master-key authentication configured. An attacker with master-key access can retrieve model-provider API keys, inspect prompts and responses, access MCP-connected tools, and abuse unrestricted pass-through endpoints to query cloud instance metadata services and obtain IAM credentials.
The exposure coincides with multiple LiteLLM flaws, including actively exploited MCP authentication bypass CVE-2026-59822, which allows arbitrary Bearer tokens to create authenticated MCP sessions, and Python code execution CVE-2026-59821 through custom code guardrails in versions before 1.82.0. Organizations should upgrade to LiteLLM 1.84.0 or later, replace and rotate default master keys, remove public access to management and MCP endpoints, restrict container egress, and enforce least-privilege cloud IAM permissions.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
CISA added actively exploited CVE-2026-59822 to its Known Exploited Vulnerabilities catalog.
Wiz observed probes against its honeypots using single-character Bearer tokens to exploit the LiteLLM MCP authentication bypass and query model-listing endpoints.
LiteLLM v1.84.0 released a fix for CVE-2026-59822, which allowed arbitrary Bearer tokens, including one-character tokens, to establish authenticated MCP sessions because of fallback authentication logic.
LiteLLM v1.82.0 released a fix for CVE-2026-59821, a post-authentication custom-code guardrail flaw that could execute arbitrary Python in the gateway container. The changes restricted unauthenticated users' default role, added administrator checks to guardrail endpoints, and applied sandboxing during guardrail registration.
In a scan of 3,074 publicly exposed LiteLLM instances, Wiz found 294 (9.6%) accepted the default "sk-1234" master key or did not require authentication; 191 instances required no authentication.
LiteLLM fixed CVE-2026-35029 in version 1.83.0. Before that release, the pass-through configuration-update route lacked an administrator authorization check, enabling unauthorized configuration of request forwarding that could be used to access internal services or cloud metadata when access controls failed.
Wiz demonstrated that a LiteLLM administrator could use unrestricted pass-through endpoints to query cloud instance-metadata services and retrieve IAM credentials, including by forwarding required IMDSv2 headers. Wiz reported no evidence that this capability had been exploited against a real deployment.
Wiz honeypots recorded exploitation of CVE-2026-42271 to install a cryptocurrency miner. The vulnerability allowed authenticated LiteLLM users to execute host commands through MCP test endpoints in affected releases.
LiteLLM fixed CVE-2026-40217 in version 1.83.10, with advisory text also referencing version 1.83.11. The flaw affected versions 1.81.8 through versions before 1.83.10 and enabled a proxy administrator to use bytecode techniques to escape the guardrail sandbox and execute code in the root-running proxy process.
Microsoft reported an August incident in which attackers executed commands in a LiteLLM gateway process, extracted environment secrets, and accessed the underlying PostgreSQL database to copy model and virtual-key records. Microsoft assessed with high confidence that the compromise began at an exposed LiteLLM gateway and matched the CVE-2026-42271 and CVE-2026-48710 attack chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcewiz.io
Open sourcedocs.litellm.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.