External risk intelligence

Bifrost MCP Client Registration Vulnerability Allows Unauthenticated Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90898

The vulnerability exists in a management API endpoint (/api/mcp/client) of a gateway service. Such services are commonly deployed in network-facing roles to handle client registrations and service orchestration, making them accessible from external networks in typical configurations.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Bifrost, a gateway service that manages MCP clients. The issue allows unauthenticated remote attackers to register clients and execute arbitrary commands with the privileges of the Bifrost process. This could enable widespread compromise if exploited.

  • Unauthenticated attackers can run commands on the gateway.
  • This critical flaw allows remote code execution without a password.
  • Confirm Bifrost exposure to prevent unauthorized access.

Attack Path

How an attacker could exploit the issue

An attacker can reach the Bifrost gateway and register a malicious MCP client without any authentication. This is possible because the management API in some versions of Bifrost does not require authentication for client registration. Once a client is registered, Bifrost will automatically start the associated program in the gateway, allowing the attacker to run arbitrary commands with the privileges of the Bifrost process.

  • Unauthenticated network access required.
  • Registering an MCP client triggers the vulnerability.
  • Arbitrary code execution as Bifrost process.

Live Threat

Current exploitation, exposure, and threat context

When authentication is disabled, an unauthenticated attacker could run arbitrary commands as the Bifrost process user on systems using an affected version of the transports library. This could impact system integrity and availability.

  • Arbitrary command execution.
  • Unauthenticated API access.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for the Bifrost service and its gateway infrastructure should lead remediation efforts. The initial step is to locate all instances of the affected Bifrost service, assess their network exposure and business criticality, and identify the specific owner accountable for each instance before planning remediation based on risk.

  • Service and infrastructure teams should own.
  • Verify unauthenticated client registration access.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Bifrost software?

Bifrost is a gateway service designed to manage MCP (Model Context Protocol) clients. It acts as an intermediary, allowing systems to register and orchestrate client programs. Users typically rely on it to integrate various tools and services by registering them through its management API, which then executes those programs within the gateway's environment.

Why is CVE-2026-90898 considered a security weakness?

This vulnerability involves Improper Access Control (CWE-284) and a Missing Authentication for Critical Function (CWE-306). It occurs because the management API allows the registration of stdio-based clients without verifying the caller's identity. Because the system automatically executes these registered programs, it permits unauthorized users to run arbitrary commands on the server.

How does an attacker trigger this vulnerability?

An attacker triggers the flaw by sending an unauthenticated POST request to the /api/mcp/client endpoint. This action registers a malicious program, which Bifrost immediately executes with the privileges of the system's process user. Note that if you are using the transports/v2.1.0 library, the system correctly blocks these unauthenticated registration attempts with a 403 error, effectively preventing the attack.

Is my instance of Bifrost at risk?

Halo Surface Signal indicates that Bifrost instances are likely at risk if they are deployed in network-facing roles. Because the vulnerability exists in a management API often used for service orchestration, any gateway exposed to an external network can be reached by unauthorized actors. If your service is strictly internal or requires authentication, the risk level changes, but you should verify your specific configuration.

How do I secure my Bifrost installation?

The immediate priority is to identify all Bifrost instances in your environment and confirm their current version and network configuration. If you are running a version using a transports library earlier than v2.1.0, you should prioritize upgrading. Additionally, ensure that governance.auth_config.is_enabled is set to true to enforce required authentication for API requests.

References