03 September 2026
Reference: CVE-2026-59822
1. What is being reported?
The LiteLLM software, which acts as a gateway for AI services, has a flaw in its authentication process. Attackers can send fake authorisation details to bypass security checks and gain unauthorised access to internal tools. This issue has been fixed in the latest version 1.84.0.
2. What this means in plain English
If your organisation uses LiteLLM, attackers could potentially access sensitive AI tools or data without needing valid login credentials. This could lead to data breaches or misuse of your AI services, impacting your business operations and reputation.
3. Could this affect a small business?
Small businesses or charities using BerriAI LiteLLM, especially versions before 1.84.0, are at risk. If you do not use this software or use a cloud service that manages it for you, you are likely not affected. Check with your IT provider to be sure.
4. What to do now
- Check if your organisation uses BerriAI LiteLLM and identify the version installed.
- If using a version before 1.84.0, arrange to update to version 1.84.0 or later immediately.
- If you rely on a cloud service for AI tools, confirm with your provider that they have applied the necessary updates or mitigations.
- Review your systems for any unusual activity and follow your IT provider’s advice on additional security measures.
5. Ask your IT provider
Are we using BerriAI LiteLLM, and if so, have we updated it to version 1.84.0 or later to address the known authentication vulnerability CVE-2026-59822?
6. Bottom line
Update BerriAI LiteLLM promptly to prevent unauthorised access and protect your AI services.
Information based on CISA KEV, NVD, and reputable security reporting.