wiz · Crawled Sep 10, 2026
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
4 IoCs 3 CVEs
Read original article ↗
AI Summary
Multiple critical vulnerabilities were discovered in LiteLLM, a popular open-source LLM gateway, enabling authentication bypass, remote code execution, and cloud credential theft. CVE-2026-59822 allows unauthenticated access to MCP endpoints via a Bearer token bypass, while CVE-2026-59821 enables post-authentication root-level RCE through unsandboxed custom code guardrails. A default master key (sk-1234) is accepted by 9.6% of public instances, allowing attackers to achieve admin access and exploit these vulnerabilities. Additionally, pass-through endpoints can be abused to exfiltrate cloud metadata and IAM credentials, especially when combined with default or missing authentication.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 18 techniques
T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1048 Exfiltration Over Alternative Protocol · Exfiltration T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1211 Exploitation for Defense Evasion · Defense Evasion T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1053.005 Scheduled Task · Execution T1204.001 Malicious Link · Execution