Same Proxy, Same Keys, a Different Way In: LiteLLM's Auth Bypass Chain
In May, a SQL injection reached LiteLLM's stored credentials through its auth check. Four months later, a three-bug chain skipped the database entirely and read live provider keys straight out of the running process, and researchers have tied active exploitation to Qilin ransomware affiliates.
LiteLLM is an API gateway that sits between applications and more than a hundred upstream model providers, handling routing, rate limits, and credential management for every call that passes through it. In May, this site covered CVE-2026-42208, a pre-authentication SQL injection that let attackers query the proxy's database directly through its own token-verification path. The lesson then was that an authentication check built to reject bad requests had itself become the way in. A separate, three-bug chain disclosed the same month, patched in the same release, and now tied to a named ransomware group, makes the same point through a different mechanism, and does not touch the database at all.
The Same Keys, a Different Extraction Method
May's SQL injection targeted two tables by name: the credentials table holding upstream provider API keys, and the configuration table holding proxy runtime secrets. Whoever built that exploit knew LiteLLM's schema in advance and queried it directly.
The newer chain skips the database entirely. LiteLLM holds live credentials for every configured provider in the memory of its own running process, since a request can arrive for any provider at any moment and the proxy needs the relevant key on hand without a lookup each time. That design choice means a single read of the process's memory exposes everything the proxy currently holds at once: OpenAI keys, AWS secrets, admin credentials, in one pass, with no query and no table name required. Different mechanism, same target: whatever LiteLLM is trusted to hold on an organization's behalf.
Three Bugs, No Password Required
The newer chain does not need a valid key at all. Wiz and RuntimeAI have confirmed Qilin affiliates using three flaws together, all patched by early summer:
CVE-2026-59822 is an improper-authentication flaw in LiteLLM's MCP Streamable HTTP endpoint. An OAuth2 passthrough fallback mechanism can stand in for a failed key validation, and a single malformed Bearer token is enough to open a session without ever holding a valid LiteLLM key. This is the entry point: it opens the door before anything else in the chain runs.
CVE-2026-48710, nicknamed BadHost, is a Host header validation bypass in Starlette, the ASGI framework LiteLLM and a large share of the Python web ecosystem build on. A crafted Host header causes the framework's routing layer to evaluate a different route than the one actually dispatched to a handler, slipping the forged session past whatever route-based authentication gate would normally sit in front of more sensitive endpoints.
CVE-2026-42271 is the payload: a command execution flaw in LiteLLM's Model Context Protocol test and preview functionality. The test-connection and list-tools endpoints passed caller-supplied command, argument, and environment values straight to a subprocess call with no validation.
Individually, each of these was disclosed and patched as its own advisory. Wiz and RuntimeAI have confirmed Qilin chaining all three: the forged Bearer token opens a session, the Host header bypass routes it somewhere it should not reach, and the command execution flaw runs whatever the attacker sends. CISA added CVE-2026-42271 to the KEV catalog on June 9; CVE-2026-59822 followed in the September 2 batch.
Who Is Using It
Wiz has linked exploitation of this chain to affiliates of the Qilin ransomware group, also tracked as Agenda. Once inside, the observed pattern is not immediate ransomware deployment. Attackers fingerprint the host, terminate any competing cryptomining processes already running, deploy an XMRig miner via an ELF binary, and read the running LiteLLM process's memory directly for whatever provider keys and admin credentials it currently holds, the same category of material May's SQL injection was built to reach, retrieved without a single database query.
This chain is worth keeping distinct from a separate finding: Obsidian Security's June disclosure of three chained LiteLLM vulnerabilities, CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217, rated CVSS 9.9 as a path from a default low-privilege user to administrator access and remote code execution. Both surfaced around the same time and both involve chained LiteLLM bugs, but public reporting ties confirmed in-the-wild exploitation to the Qilin chain above, not to Obsidian's research disclosure. Treating them as the same incident would overstate what is confirmed about one and understate the other.
The September 2 KEV batch that added CVE-2026-59822 also included a Kestra workflow-engine flaw tied to a separate late-June intrusion involving a reverse shell and cryptomining, a similar playbook to the chain above, though not confirmed to be connected to it.
The Throughline
A gateway sitting between every application and every model provider is, structurally, a single point holding the keys to all of them. SQL injection and a three-bug auth-forgery chain are unrelated vulnerability classes, and one queries a database while the other reads a process's memory directly, skipping the database altogether. Both, inside the same product, inside the same few months, reached the same material. The vulnerability class keeps changing. What it leads to does not.