Description
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.



The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).



 transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Bifrost, a gateway service, allows clients to register command‑line “stdio” programs via a management API. When a client is added, Bifrost launches that program immediately, without any MCP handshake. The default configuration has governance.auth_config.is_enabled set to false, meaning the API accepts any request as an administrator. A single unauthenticated POST to /api/mcp/client therefore causes arbitrary code to run as the Bifrost process user (appuser on the official image), providing a direct remote code execution vector backed by a fundamental access‑control weakness (CWE‑284) and lack of authentication (CWE‑306).

Affected Systems

This flaw affects Bifrost HTTP transport releases 1.6.x through 1.6.11 and the transports/v2.0.0 series. The 2.1.0 release and later contain a 403 response for unauthenticated stdio registrations, removing the vulnerability. Users running older versions with default settings are fully vulnerable.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is considered critical; the EPSS score is not provided, but the absence of authentication and the existence of administrative functionality make exploitation straightforward. Attackers only need to send an unauthenticated POST request to the management endpoint, which can be done from any network location that can reach the Bifrost instance. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and ease of exploitation warrant immediate attention.

Generated by OpenCVE AI on September 15, 2026 at 14:41 UTC.

Remediation

Vendor Solution

Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change.


Vendor Workaround

Set governance.auth_config.is_enabled to true, use strong administrator credentials, and firewall the management listener.


OpenCVE Recommended Actions

  • Upgrade Bifrost HTTP transport to 2.1.0 or later
  • Enable governance.auth_config.is_enabled to true
  • Restrict access to the management interface by firewalling or using strong administrator credentials

Generated by OpenCVE AI on September 15, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Maximhq
Maximhq bifrost
Vendors & Products Maximhq
Maximhq bifrost

Mon, 14 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).  transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
Title Bifrost unauthenticated remote code execution via MCP stdio client registration
Weaknesses CWE-284
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-09-14T11:19:46.276Z

Reserved: 2026-09-14T10:13:28.161Z

Link: CVE-2026-90898

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:49.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:08.237

Modified: 2026-09-18T19:31:11.370

Link: CVE-2026-90898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function