PT-2026-91161 · Unknown · Bifrost Transports

CVE-2026-90898

·

Published

2026-09-14

·

Updated

2026-10-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bifrost HTTP transport versions prior to 2.1.0
Description Bifrost allows the registration of MCP clients through its management API, where a stdio client consists of a command and arguments. The software starts the program in the gateway immediately upon client addition without requiring an MCP handshake. Because the default configuration has governance.auth config.is enabled set to false, every caller is treated as a local administrator. An unauthenticated POST request to the '/api/mcp/client' endpoint allows an attacker to execute arbitrary commands as the Bifrost process user. This issue can be exploited to expose stored LLM provider API keys and enable lateral movement across AI infrastructure. Real-world incidents have been reported where attackers achieved immediate remote code execution through this flaw.
Recommendations Update Bifrost HTTP transport to version 2.1.0 or later. Enable management authentication. Restrict network access to the management interface to trusted IP addresses only.

Exploit

Fix

RCE

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90898

Affected Products

Bifrost Transports