PatchSiren

maximhq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL maximhq CVE published 2026-09-14

CVE-2026-90898

CVE-2026-90898 is a critical vulnerability in the Bifrost management API that allows unauthenticated clients to register and execute arbitrary programs as the Bifrost process user. The default configuration has authentication disabled, making it trivial for attackers to exploit. A fix is available in transports/v2.1.0, which refuses unauthenticated stdio registrations with a 403 error.