{"api_version":"1","generated_at":"2026-09-15T08:17:01+00:00","cve":"CVE-2026-90898","urls":{"html":"https://cve.report/CVE-2026-90898","api":"https://cve.report/api/cve/CVE-2026-90898.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90898","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90898"},"summary":{"title":"Bifrost unauthenticated remote code execution via MCP stdio client registration","description":"Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.\n\n\n\nThe default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).\n\n\n\n transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.","state":"PUBLISHED","assigner":"JFROG","published_at":"2026-09-14 11:17:08","updated_at":"2026-09-14 12:17:51"},"problem_types":["CWE-284","CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"reefs@jfrog.com","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/maximhq/bifrost/pull/6757","name":"https://github.com/maximhq/bifrost/pull/6757","refsource":"reefs@jfrog.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/maximhq/bifrost/releases/tag/transports/v2.1.0","name":"https://github.com/maximhq/bifrost/releases/tag/transports/v2.1.0","refsource":"reefs@jfrog.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/maximhq/bifrost","name":"https://github.com/maximhq/bifrost","refsource":"reefs@jfrog.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/maximhq/bifrost/commit/12e170352bd25eab1ae9ba16611f1797d1fd8fdc","name":"https://github.com/maximhq/bifrost/commit/12e170352bd25eab1ae9ba16611f1797d1fd8fdc","refsource":"reefs@jfrog.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90898","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90898","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"maximhq","product":"Bifrost","version":"affected 2.1.0 semver","platforms":["Linux","macOS"]}],"timeline":[{"source":"CNA","time":"2026-07-13T10:27:00.000Z","lang":"en","value":"Reported to the Bifrost maintainers (GHSA-86gf-xh3g-rvxq)"},{"source":"CNA","time":"2026-09-02T15:14:00.000Z","lang":"en","value":"Fix merged upstream (PR #6757)"},{"source":"CNA","time":"2026-09-08T15:15:00.000Z","lang":"en","value":"Fix first shipped in Bifrost HTTP v2.1.0"}],"solutions":[{"source":"CNA","title":"","value":"Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Set governance.auth_config.is_enabled to true, use strong administrator credentials, and firewall the management listener.","time":"","lang":"en"}],"exploits":[{"source":"CNA","title":"","value":"JFrog has a private proof of concept. An unauthenticated POST /api/mcp/client with connection_type stdio and attacker-chosen command and args starts the program in the gateway. Public exploit details are not included in this record.","time":"","lang":"en"}],"credits":[{"source":"CNA","value":"Yuval Moravchick | JFrog","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-90898","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-14T11:01:44.207374Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-14T11:19:46.276Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://github.com/maximhq/bifrost","defaultStatus":"unaffected","modules":["transports/bifrost-http","core/mcp"],"packageName":"github.com/maximhq/bifrost/transports","platforms":["Linux","macOS"],"product":"Bifrost","programFiles":["transports/bifrost-http/handlers/mcp.go","transports/bifrost-http/handlers/middlewares.go"],"repo":"git://github.com/maximhq/bifrost","vendor":"maximhq","versions":[{"lessThan":"2.1.0","status":"affected","version":"0","versionType":"semver"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Management API reachable and governance.auth_config.is_enabled=false, which is the documented default. Confirmed on maximhq/bifrost v1.6.3. Fixed in transports/v2.1.0 (2026-09-08). An operator who enables management authentication and keeps the admin listener off untrusted networks is not exposed to the unauthenticated form of this issue.</p>"}],"value":"Management API reachable and governance.auth_config.is_enabled=false, which is the documented default. Confirmed on maximhq/bifrost v1.6.3. Fixed in transports/v2.1.0 (2026-09-08). An operator who enables management authentication and keeps the admin listener off untrusted networks is not exposed to the unauthenticated form of this issue."}],"credits":[{"lang":"en","type":"finder","value":"Yuval Moravchick | JFrog"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.</p><p>The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).</p><p>&nbsp;transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.</p>"}],"value":"Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.\n\n\n\nThe default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).\n\n\n\n transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it."}],"exploits":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>JFrog has a private proof of concept. An unauthenticated POST /api/mcp/client with connection_type stdio and attacker-chosen command and args starts the program in the gateway. Public exploit details are not included in this record.</p>"}],"value":"JFrog has a private proof of concept. An unauthenticated POST /api/mcp/client with connection_type stdio and attacker-chosen command and args starts the program in the gateway. Public exploit details are not included in this record."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-14T10:18:53.454Z","orgId":"48a46f29-ae42-4e1d-90dd-c1676c1e5e6d","shortName":"JFROG"},"references":[{"name":"PR #6757: refuse unauthenticated stdio MCP registration","tags":["patch"],"url":"https://github.com/maximhq/bifrost/pull/6757"},{"name":"Merge commit for PR #6757","tags":["patch"],"url":"https://github.com/maximhq/bifrost/commit/12e170352bd25eab1ae9ba16611f1797d1fd8fdc"},{"name":"Bifrost HTTP v2.1.0 (first release containing the fix)","tags":["release-notes"],"url":"https://github.com/maximhq/bifrost/releases/tag/transports/v2.1.0"},{"name":"Bifrost repository","tags":["product"],"url":"https://github.com/maximhq/bifrost"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change.</p>"}],"value":"Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change."}],"source":{"discovery":"EXTERNAL"},"timeline":[{"lang":"en","time":"2026-07-13T10:27:00.000Z","value":"Reported to the Bifrost maintainers (GHSA-86gf-xh3g-rvxq)"},{"lang":"en","time":"2026-09-02T15:14:00.000Z","value":"Fix merged upstream (PR #6757)"},{"lang":"en","time":"2026-09-08T15:15:00.000Z","value":"Fix first shipped in Bifrost HTTP v2.1.0"}],"title":"Bifrost unauthenticated remote code execution via MCP stdio client registration","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Set governance.auth_config.is_enabled to true, use strong administrator credentials, and firewall the management listener.&nbsp;</p>"}],"value":"Set governance.auth_config.is_enabled to true, use strong administrator credentials, and firewall the management listener."}],"x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"48a46f29-ae42-4e1d-90dd-c1676c1e5e6d","assignerShortName":"JFROG","cveId":"CVE-2026-90898","datePublished":"2026-09-14T10:18:53.454Z","dateReserved":"2026-09-14T10:13:28.161Z","dateUpdated":"2026-09-14T11:19:46.276Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-14 11:17:08","lastModifiedDate":"2026-09-14 12:17:51","problem_types":["CWE-284","CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"reefs@jfrog.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-14T11:01:44.207374Z","id":"CVE-2026-90898","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90898","Ordinal":"1","Title":"Bifrost unauthenticated remote code execution via MCP stdio clie","CVE":"CVE-2026-90898","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90898","Ordinal":"1","NoteData":"Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.\n\n\n\nThe default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).\n\n\n\n transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.","Type":"Description","Title":"Bifrost unauthenticated remote code execution via MCP stdio clie"}]}}}