wiz · Crawled Sep 10, 2026

Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise

4 IoCs 3 CVEs
Read original article ↗

AI Summary

Multiple critical vulnerabilities were discovered in LiteLLM, a popular open-source LLM gateway, enabling authentication bypass, remote code execution, and cloud credential theft. CVE-2026-59822 allows unauthenticated access to MCP endpoints via a Bearer token bypass, while CVE-2026-59821 enables post-authentication root-level RCE through unsandboxed custom code guardrails. A default master key (sk-1234) is accepted by 9.6% of public instances, allowing attackers to achieve admin access and exploit these vulnerabilities. Additionally, pass-through endpoints can be abused to exfiltrate cloud metadata and IAM credentials, especially when combined with default or missing authentication.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 4 extracted

Type Value Detail
Filename user_api_key_auth_mcp.py Details →
Filename guardrail_endpoints.py Details →
Filename pass_through_endpoints.py Details →
SHA-256 sk-1234 Details →

MITRE ATT&CK TTPs 18 techniques