# Bifrost AI gateway flaw permits unauthenticated command execution

_Published Tuesday, September 22, 2026 at 3:12 PM EDT · Security, AI · Latest · Tier 1 — Major_

![Bifrost AI gateway flaw permits unauthenticated command execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieRvfWKvxkIOajVIJ1qC7l54ZBCtHMwZTfUHGqSZ_35vGzAl23py6GfaqrxYkcfWZ_K75t9BGC6btqJQiS9jwaV7O4kJsCSIIQxmn9VnZrBbdjxSN4AzQ05K9G-ES82qV1G6IUcsBetsb0mVO5e5IHTr2FyAA3gtCN8Vne5N1H5Swgd2FLLlwi0GXFQ0o/s1700-nu-rw-lo-l85-e365/bifrost.jpg)

A critical Bifrost vulnerability lets an unauthenticated attacker execute arbitrary commands on servers running affected versions of the open-source AI gateway. CVE-2026-90898 affects the HTTP transport before version 2.1.0 when management authentication is disabled, the default setting.

An attacker can register a standard-input-and-output Model Context Protocol client through one POST request, causing Bifrost to start a chosen command as the gateway user. That access can expose credentials for connected model providers. The stock binary limits the management interface to localhost, but the official Docker image listens on all interfaces. Version 2.1.0 fixes the flaw; neither Bifrost vulnerability was listed as actively exploited at publication.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html)

---
Canonical: https://techandbusiness.org/newswire/6ukKWVjBTiZq9Q8XZcwIND
Published: 2026-09-22T19:12:23.921Z
Story chronology: 2026-09-22T16:41:12.000Z
Retrieved: 2026-09-22T20:38:02.975Z
Publisher: Tech & Business (techandbusiness.org)
