⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

September 22, 2026

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials Swati KhandelwalSep 22, 2026Artificial Intelligence / Vulnerability A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration. A fix is available in transports/v2.1.0. Yuval Moravchick of JFrog Security Research, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client. Bifrost starts the…

CVEs: CVE-2026-90898, CVE-2026-86242, CVE-2026-55245