The record
Written from the 1 report below. Nothing here is unsourced.
- A flaw tracked as CVE-2026-90898 allows attackers to run arbitrary commands on Bifrost gateway servers.
- The vulnerability exists because management authentication is disabled by default in the software.
- Attackers can register a malicious MCP client to execute code as the gateway process user.
- Users are urged to upgrade to version 2.1.0 or enable authentication to prevent unauthorized access to credentials.
What to watch next
- Check if CVE-2026-90898 is added to the CISA Known Exploited Vulnerabilities catalog.
- Ensure Bifrost management API is not reachable from untrusted networks.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Yuval Moravchick
JFrog Security Research
1 quote · 1 outlet
“an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client.”
In the article
…transport before 2.1.0 when management authentication is disabled, which is the default configuration. A fix is available in transports/v2.1.0. Yuval Moravchick of JFrog Security Research, who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client. Bifrost starts the specified command immediately, before any MCP handshake, as the gateway process user. On the official Docker image, that user is appuser. Because the gateway stores API keys for every connected…
Coverage1
All filed from India
Named United States · Bifrost · JFrog Security Research · Or Peles · Yuval Moravchick
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
