CRITICAL
maximhq
CVE published 2026-09-14
CVE-2026-90898
CVE-2026-90898 is a critical vulnerability in the Bifrost management API that allows unauthenticated clients to register and execute arbitrary programs as the Bifrost process user. The default configuration has authentication disabled, making it trivial for attackers to exploit. A fix is available in transports/v2.1.0, which refuses unauthenticated stdio registrations with a 403 error.