CRITICALVulnerability
CVE-2026-90898
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
Properties
- severity
- CRITICAL
- score
- 9.8
- cve_id
- CVE-2026-90898
- signal_observed_at
- 2026-09-23T22:45:07+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-09-14T11:17:08.237
- last_modified
- 2026-09-18T19:31:11.370
Related Entities (3)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (2)
→[Weakness]Missing Authentication for Critical Function
→[Weakness]Improper Access Control
Explore deeper with Ninja Signal's threat intelligence graph