Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical AI Gateway Flaw Exposes Bifrost to Command Attacks

Critical AI Gateway Flaw Exposes Bifrost to Command Attacks

Posted on September 22, 2026 By CWS

A serious security vulnerability has been identified in Bifrost, an open-source AI gateway that facilitates requests to over 20 large language model (LLM) providers. This flaw enables attackers to execute arbitrary commands on the server without authentication, posing a significant risk to systems using this gateway.

Details of the Bifrost Vulnerability

The vulnerability, cataloged as CVE-2026-90898 with a CVSS score of 9.8, affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled by default. A resolution has been provided in the latest update, transports/v2.1.0. Discovered by Yuval Moravchick from JFrog Security Research, the issue allows an unauthorized user to register a stdio-type MCP client through a single POST request to the management API endpoint.

Upon registration, Bifrost initiates the specified command without any MCP handshake, operating under the gateway process user, known as appuser on the official Docker image. This setup grants the attacker access to API keys for all connected providers, severely compromising security.

Mitigation Steps and Recommendations

Operators are strongly advised to upgrade to transports/v2.1.0, which denies unauthenticated client registration by returning a 403 error. For those unable to upgrade immediately, enabling governance authentication, using robust credentials, and ensuring the management listener is not exposed to untrusted networks are critical steps for protection.

JFrog recommends treating any instance with disabled authentication and exposed management API as compromised. Rotating virtual and provider API keys is essential to secure the system. It’s important to note that the transports/v2.0.0 version does not fix the unauthenticated registration issue, only an earlier plugin vulnerability.

Additional Security Concerns

Another vulnerability discovered by Or Peles from the same research team, identified as CVE-2026-86242 with a CVSS score of 8.1, allows attackers to register a custom plugin using an HTTP URL. This flaw permits the downloading and loading of a potentially malicious shared object file, which runs under the gateway process user in dynamically linked builds.

Both vulnerabilities stem from Bifrost’s management API being shipped with authentication turned off by default. These issues follow a recent pattern of security disclosures, including an SSRF flaw fixed in August 2026, illustrating ongoing challenges in AI gateway security.

The pattern of vulnerabilities, particularly the MCP flaw, highlights potential for real-world attacks, as seen in similar incidents with other AI gateways. As of now, neither Bifrost vulnerability has been added to the Known Exploited Vulnerabilities catalog.

The Hacker News Tags:AI security, API security, Bifrost, command execution, CVE-2026-86242, CVE-2026-90898, Cybersecurity, JFrog Research, LLM providers, Vulnerability

Post navigation

Previous Post: PowerShell Exploited in New TASK#STOMP Cyber Intrusion
Next Post: Veeam Agent Vulnerability Exploited for SYSTEM Privileges

Related Posts

TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution The Hacker News
Interrupt Injection: New Attack Bypasses CPU Defenses Interrupt Injection: New Attack Bypasses CPU Defenses The Hacker News
Critical Cisco Flaws Fixed: IMC and SSM Security Updates Critical Cisco Flaws Fixed: IMC and SSM Security Updates The Hacker News
Citrix Urges Immediate Patching of Critical NetScaler Flaws Citrix Urges Immediate Patching of Critical NetScaler Flaws The Hacker News
Securing the Mid-Market Across the Complete Threat Lifecycle Securing the Mid-Market Across the Complete Threat Lifecycle The Hacker News
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark