CVE-2026-90898 is an unauthenticated remote code execution vulnerability in Bifrost's management API. Bifrost accepts registration of stdio Model Context Protocol (MCP) clients containing a program command and arguments, then starts that program immediately when the client is added, without requiring an MCP handshake. Management authentication is disabled by default, allowing an unauthenticated caller to register a malicious stdio client through the management endpoint and execute an attacker-specified program as the Bifrost gateway process user. The issue affects Bifrost HTTP transports before version 2.1.0 when management authentication is disabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote command-execution vulnerability in Bifrost's MCP-client management API. An attacker can submit a single POST request to register a stdio-type MCP client, causing Bifrost to immediately execute an attacker-specified command as the gateway process user.
An unauthenticated remote code execution vulnerability in Bifrost's MCP-client management API. With authentication disabled by default, an unauthenticated caller can register a stdio MCP client through POST /api/mcp/client and cause Bifrost to execute an attacker-supplied command as the Bifrost process user.
An unauthenticated remote code execution vulnerability in Bifrost's MCP-client management API. With authentication disabled by default, an unauthenticated caller can submit a stdio MCP-client registration to POST /api/mcp/client and cause Bifrost to execute an arbitrary command as its process user.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.