EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

Un'importante vulnerabilità critica in Bifrost, un gateway AI open-source, permette a un attaccante non autenticato di eseguire comandi arbitrari sul server gateway con una singola richiesta HTTP. La vulnerabilità, identificata come CVE-2026-90898, colpisce tutte le versioni di Bifrost HTTP transport prima di 2.1.0 quando l'autenticazione è disattivata. La patch è disponibile in transports/v2.1.0.

Why it matters

Per le PMI italiane, questa vulnerabilità rappresenta un rischio elevato per la sicurezza dei dati e delle infrastrutture, poiché consente agli attaccanti di ottenere accesso alle credenziali API di provider LLM. La mancanza di autenticazione predefinita espone le aziende a potenziali compromissioni e attacchi di tipo command injection.

Potential operational benefits

  • Riduzione della superficie esposta
  • Prevenzione di attacchi di tipo command injection
  • Miglioramento del controllo sugli accessi
  • Aumento della visibilità e della risposta agli incidenti
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteFirewall NGFW / IPSMonitoraggio / SIEMMFA / Identità
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 18:41
MITRE ATT&CK
T1486, T1190
CVE
CVE-2026-90898
Classification
Critical
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source