On September 14, 2026, the CVE record published CVE-2026-90898, a critical access-control vulnerability in Bifrost's HTTP transport. The affected management API could accept an unauthenticated stdio MCP-client registration when dashboard authentication was disabled or not configured. Registering that client causes Bifrost to start the supplied program as a subprocess of the gateway.
Bifrost HTTP v2.1.0 contains the fix. If an affected management API was reachable, upgrade and investigate before assuming network placement alone prevented misuse.
What happened
Bifrost supports MCP clients that communicate over HTTP, SSE, or standard input and output. A stdio client is intentionally defined by a command and arguments because the gateway must start the local MCP server.
In transports v2.0.0, Bifrost's default-open management posture also applied to stdio client registration. That combined two individually understandable features into a dangerous boundary failure: a network caller who had not authenticated could ask the gateway to start a process.
The fix commit rejects stdio registration when the request reached the handler without a real credential check. It preserves stdio registration for authenticated administrators and configuration-file provisioning for operators with host access. The same change restricts unauthenticated HTTP or SSE MCP registrations that target private, loopback, link-local, or carrier-grade NAT addresses.
Who was exposed
A deployment needed all of the following for the command-execution path described by CVE-2026-90898:
- Bifrost HTTP transport earlier than v2.1.0 (including v2.0.0; the 1.6.x line through 1.6.11 also lacks the fix)
- Dashboard authentication disabled or not configured
- Network access to the MCP client-management endpoint
- Permission for the Bifrost process to start the requested program
The CNA CVE record assigns a CVSS 3.1 score of 9.8. That severity describes the vulnerable boundary, not proof that any particular deployment was compromised.
Was VibeScan affected?
No Bifrost package, binary, container reference, or configuration is present in the VibeScan repository. The repository evidence therefore shows no direct dependency exposure; production operators should still verify deployed inventory before treating that conclusion as complete.
This issue is still relevant to VibeScan's audience. AI applications increasingly put gateways and MCP servers behind web management surfaces, and those surfaces can turn administrative features into remote execution when authentication is optional or bypassed.
How to check your deployment
- Confirm the exact Bifrost HTTP transport version in the deployed image or binary, not only a local configuration file.
- Determine whether the MCP management API was reachable from untrusted networks during the affected period.
- Confirm whether dashboard authentication was enabled and actually enforced on management requests.
- Inventory stdio MCP clients and compare their creation times, commands, arguments, and owners with approved changes.
- Review gateway and host telemetry for unexpected child processes, outbound connections, persistence, or file changes.
Preserve non-sensitive logs and deployment metadata before making changes that would erase the investigation timeline.
Immediate response
- Upgrade to Bifrost HTTP v2.1.0 or later.
- Enable dashboard authentication and require it for every management endpoint.
- Restrict the management API at the network layer to trusted operator paths.
- Remove unapproved MCP clients and investigate any process they started before rotating credentials.
- Rotate credentials available to the gateway if investigation finds evidence of unauthorized command execution.
What VibeScan detects today
VibeScan does not currently claim detection of Bifrost versions, Bifrost management authentication, or exploitation of this issue. Its URL scan may identify general externally observable web-security weaknesses, but that does not prove whether this MCP administration boundary is safe.
For this vulnerability, use deployment inventory, Bifrost configuration review, access logs, and host-level process telemetry. A future VibeScan check must have a tested, externally observable signal before it is described as detection.
Primary sources
- CNA record for CVE-2026-90898
- NVD record for CVE-2026-90898
- Bifrost remediation commit
- Bifrost HTTP v2.1.0 release
Last reviewed: October 5, 2026.