The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).
transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
No advisories yet.
Solution
Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change.
Workaround
Set governance.auth_config.is_enabled to true, use strong administrator credentials, and firewall the management listener.
Mon, 14 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maximhq
Maximhq bifrost |
|
| Vendors & Products |
Maximhq
Maximhq bifrost |
Mon, 14 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it. | |
| Title | Bifrost unauthenticated remote code execution via MCP stdio client registration | |
| Weaknesses | CWE-284 CWE-306 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2026-09-14T11:19:46.276Z
Reserved: 2026-09-14T10:13:28.161Z
Link: CVE-2026-90898
Updated: 2026-09-14T11:13:49.583Z
Status : Received
Published: 2026-09-14T11:17:08.237
Modified: 2026-09-14T12:17:51.657
Link: CVE-2026-90898
No data.
OpenCVE Enrichment
Updated: 2026-09-14T12:00:13Z