CVE-2026-90898: CWE-306 Missing Authentication for Critical Function in maximhq Bifrost
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
AI Analysis
Technical Summary
Bifrost's management API registers MCP clients by starting specified programs immediately upon client addition without requiring an MCP handshake. The default configuration disables authentication (governance.auth_config.is_enabled=false), effectively granting local admin rights to any caller. An unauthenticated POST request to /api/mcp/client can execute arbitrary programs as the Bifrost process user (appuser in the official image). This issue affects all versions prior to 2.1.0. The vulnerability is addressed in transports/v2.1.0, which rejects unauthenticated stdio registrations with an HTTP 403 response.
Potential Impact
An unauthenticated attacker can execute arbitrary code on the Bifrost gateway with the privileges of the Bifrost process user. This leads to full confidentiality, integrity, and availability compromise of the affected system. The default disabled authentication setting exacerbates the risk by granting local admin rights to any caller without credentials.
Mitigation Recommendations
Upgrade to version 2.1.0 or later, which enforces authentication and rejects unauthenticated stdio client registrations with a 403 error. Until upgraded, enable authentication by setting governance.auth_config.is_enabled to true to prevent unauthorized access. No other mitigations are indicated in the advisory.
CVE-2026-90898: CWE-306 Missing Authentication for Critical Function in maximhq Bifrost
Description
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
CVSS v3.1
Score 9.8critical
Affected software
maximhq
Bifrost
pkg:github/github.com/maximhq/bifrost/transportsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Bifrost's management API registers MCP clients by starting specified programs immediately upon client addition without requiring an MCP handshake. The default configuration disables authentication (governance.auth_config.is_enabled=false), effectively granting local admin rights to any caller. An unauthenticated POST request to /api/mcp/client can execute arbitrary programs as the Bifrost process user (appuser in the official image). This issue affects all versions prior to 2.1.0. The vulnerability is addressed in transports/v2.1.0, which rejects unauthenticated stdio registrations with an HTTP 403 response.
Potential Impact
An unauthenticated attacker can execute arbitrary code on the Bifrost gateway with the privileges of the Bifrost process user. This leads to full confidentiality, integrity, and availability compromise of the affected system. The default disabled authentication setting exacerbates the risk by granting local admin rights to any caller without credentials.
Mitigation Recommendations
Upgrade to version 2.1.0 or later, which enforces authentication and rejects unauthenticated stdio client registrations with a 403 error. Until upgraded, enable authentication by setting governance.auth_config.is_enabled to true to prevent unauthorized access. No other mitigations are indicated in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- JFROG
- Date Reserved
- 2026-09-14T10:13:28.161Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa7cd3955bf5e2cf5e9c1c7
Added to database: 09/14/2026, 10:32:25 UTC
Last enriched: 09/14/2026, 10:46:33 UTC
Last updated: 09/14/2026, 11:32:19 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.