AnalysisCybersecuritySeptember 22, 2026

Critical Bifrost AI gateway flaw allows unauthenticated command execution

Read original source →thehackernews.com

CVE-2026-90898 (CVSS 9.8) affects all Bifrost HTTP transport versions before 2.1.0 when management auth is disabled, the default. A single unauthenticated POST to /api/mcp/client registers a stdio MCP client and runs commands as the gateway user, exposing stored provider API keys.

1 source

More stories today

Open the live feed