Military & Security

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

· September 22, 2026
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

What happened

A critical security flaw in Bifrost, an open-source AI gateway that routes requests to over 20 large language model providers, allows attackers to execute arbitrary commands on the gateway server without authentication. The vulnerability, tracked as CVE-2026-90898 with a high severity score of 9.8, affects all versions of Bifrost HTTP transport prior to version 2.1.0 when management authentication is enabled.

The risk

An attacker can send a single crafted HTTP request to the vulnerable Bifrost gateway and run any command on the host machine. This bypasses protections that should require credentials and effectively gives full control over the server. Since Bifrost directs AI requests to multiple vendors, compromising the gateway could expose or alter the communication between users and language models, creating risks for data integrity and privacy.

Why it matters

Many organizations rely on Bifrost to manage connections across several proprietary and open-source LLM providers securely. This vulnerability raises the baseline risk for anyone running self-hosted AI infrastructure that handles sensitive or production workloads. Attackers exploiting the flaw could disrupt service, steal secrets, or pivot within a private network. The high severity rating signals an urgent need for patching to avoid costly breaches or chained attacks.

Who should pay attention

Operators running Bifrost gateways with HTTP transport should prioritize upgrading to version 2.1.0 or later, which patches this flaw. Security teams need to audit exposure and access policies on AI gateway infrastructure and consider tightening network controls until patches are applied. Builders and integrators depending on federated AI routing need to evaluate the risk of single points of failure introduced by vulnerable gateway components.

What to watch next

Check for new exploit tools targeting this vulnerability and monitoring updates from the Bifrost open-source community. Watch how this incident influences trust and security standards around AI middleware tools. Vendor responses from the large language model providers relying on Bifrost may also affect integration approaches and contract terms for enterprise users.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.