Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
wiz.io | vulnerability | #cloud | #rce | #cloud-security | #litellm | #wiz | #llm-gateway | #cve-2026-59822 | #cve-2026-59821
Summary
Wiz Research: ~10% of 3,000 public LiteLLM instances accept the default key sk-1234 or no auth; chaining CVE-2026-59822 (MCP bypass) and CVE-2026-59821 reaches root RCE and cloud credential theft.
- Published
- Collected
Skip to content