Critical

Bifrost, AI gateway, CVE-2026-90898, MCP, unauthenticated RCE, JFrog, LLM, command execution

Bifrost AI Gateway CVE-2026-90898: Unauth RCE

Bifrost AI Gateway CVE-2026-90898 is a CVSS 9.8 unauthenticated command execution via MCP stdio client registration. Upgrade to transports v2.1.0.

Bifrost AI Gateway CVE-2026-90898 is a critical unauthenticated command-execution flaw (CVSS 9.8, CWE-284) in the popular open-source AI gateway. An attacker can register a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the specified command immediately, before any MCP handshake, as the gateway process user. Upgrade to transports v2.1.0 now, or enable authentication and lock down the management listener.

Bifrost is an open-source AI gateway that routes requests to more than 20 LLM providers, the kind of infrastructure teams increasingly put in front of every model call. That makes an unauthenticated remote code execution bug in it a high-value target: the gateway typically holds provider API keys and sits in the path of an application's AI traffic. According to The Hacker News, JFrog Security Research's Yuval Moravchick found the flaw, with Or Peles of the same team reporting a related issue (CVE-2026-86242).

The mechanism is a textbook missing-authorization problem (CWE-284) made worse by an AI-native feature. Bifrost lets clients register Model Context Protocol (MCP) servers; the "stdio" client type tells the gateway to launch a local command and speak MCP to it over standard input and output. Because the management API ships with authentication disabled by default, an attacker can POST an stdio client definition to /api/mcp/client with no credentials, and Bifrost executes the named command right away, before any MCP handshake completes, as the gateway process user. There is no exploit chain to build; the registration itself is the code execution.

What is CVE-2026-90898 and why is the MCP angle the problem?

CVE-2026-90898 is an unauthenticated command-execution vulnerability in Bifrost's HTTP transport. The AI-specific twist is MCP: the protocol's stdio transport is designed to spawn a local process, so a feature working exactly as intended becomes remote code execution the moment the endpoint that registers those processes is reachable without authentication. It is a clean illustration of how AI-agent plumbing widens the classic attack surface, an ordinary missing-auth flaw on an ordinary API, but the API's job is to launch commands. If you are new to the protocol, our explainer on MCP security and its risks covers why these server connections are such a sharp edge.

Which Bifrost versions are affected and how do I fix it?

The flaw affects the Bifrost HTTP transport in its default, authentication-disabled configuration.

Detail

Value

CVE

CVE-2026-90898 (CVSS 9.8, CWE-284); related: CVE-2026-86242

Product

Bifrost open-source AI gateway (HTTP transport)

Affected

All versions before transports v2.1.0 when management auth is disabled (the default); v2.0.0 also vulnerable to the MCP flaw

Fix

Upgrade to transports/v2.1.0, which blocks unauthenticated stdio MCP client registration

Workaround

Enable management authentication and restrict the management listener to trusted networks

Exploited

No evidence in the wild at disclosure; not in CISA KEV

Upgrade to transports v2.1.0, and regardless of version, enable authentication on the management API and keep that listener off untrusted networks. Because the gateway likely holds LLM provider keys, rotate any credentials that were reachable while an unauthenticated instance was exposed.

Is CVE-2026-90898 being exploited?

There is no evidence of in-the-wild exploitation at disclosure, and it is not in CISA's KEV catalog. That is the window to act in, not a reason to wait: an unauthenticated RCE that is default-on and requires only a single POST is trivial to weaponize once the detail is public, and EPSS already sits around the 28th percentile with the technique fully documented.

Our read

The lesson here is not that MCP is unsafe but that AI-agent infrastructure inherits every old rule about authentication, and then raises the stakes, because the endpoints in question launch processes and hold model keys. A gateway that ships with management auth off by default is a configuration decision that turns a convenience into an unauthenticated shell. This is where understanding your real exposure beats trusting a default: inventory the AI gateways, agent orchestrators, and MCP endpoints in your stack, and prove that each privileged endpoint actually demands an authenticated caller rather than assuming it does. As teams wire models into everything, the fastest-growing attack surface is the glue, and the glue is exactly what nobody is scanning.

Reporting by The Hacker News; CVSS 9.8, CWE-284, affected versions, and fix per JFrog Security Research (Yuval Moravchick, Or Peles) and the project advisory. Sources linked above.

Frequently asked questions

What is CVE-2026-90898?
It is a critical unauthenticated command-execution flaw (CVSS 9.8, CWE-284) in the Bifrost open-source AI gateway. An unauthenticated POST to /api/mcp/client registering a stdio MCP client makes Bifrost run the specified command as the gateway process user.

How do I fix CVE-2026-90898?
Upgrade to Bifrost transports v2.1.0, which blocks unauthenticated stdio MCP client registration. Also enable authentication on the management API, restrict the listener to trusted networks, and rotate any provider keys that were exposed.

Is CVE-2026-90898 being exploited in the wild?
No confirmed exploitation at disclosure, and it is not in CISA KEV. But it is default-on and needs only one unauthenticated request, so it is quick to weaponize, patch without waiting.

Why does the MCP stdio feature cause this?
MCP's stdio transport is meant to spawn a local process and communicate over standard input and output. When the endpoint that registers those processes is reachable without authentication, that intended behavior becomes remote command execution.

Writing your own code with AI? The same bug classes surface there too. Scan your code free with Argus ›
Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.
AI CODE SECURITY
Catch the bug before it ships
Argus scans your repos for the vulnerability classes behind today's CVEs.
›Prioritized by real exploit data
›Connect a repo in minutes
Run a free scan
Live NVD · EPSS · CISA KEV