The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

A critical vulnerability (CVE-2026-90898, CVSS 9.8) in Bifrost, an open-source AI gateway routing requests to over 20 LLM providers, allows unauthenticated remote code execution through a single HTTP request. Discovered by JFrog Security Research in September 2026, the flaw affects all versions before 2.1.0 when management authentication is disabled (the default configuration). Attackers can register malicious MCP clients via the management API endpoint, gaining immediate command execution and access to stored API keys for all connected AI providers. The official Docker image exposes this vulnerability to external networks by binding to 0.0.0.0.

This incident highlights the growing security risks in the rapidly expanding AI infrastructure ecosystem, where authentication-by-default failures create critical attack surfaces. With AI gateways becoming central chokepoints for enterprise AI workflows and storing sensitive provider credentials, these vulnerabilities represent a new class of high-impact targets for attackers seeking to compromise AI operations at scale.

Why This Matters Now

AI gateway vulnerabilities are becoming a critical attack vector as organizations centralize their AI infrastructure. With enterprises increasingly relying on AI gateways to manage multiple LLM providers and API keys, these systems represent high-value targets that can compromise entire AI operations through a single vulnerability.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers can send a single unauthenticated POST request to the /api/mcp/client endpoint to register a malicious MCP client, which Bifrost immediately executes as a command with gateway process privileges.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this AI gateway exploitation by limiting attacker reachability through segmentation and controlled access paths. The blast radius across AI infrastructure components would likely have been significantly reduced through east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation and application-aware policies would likely have constrained the attacker's ability to reach vulnerable management endpoints from untrusted network segments or external locations

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload isolation policies would likely have limited the compromised process's access scope to credential stores and sensitive configuration data through container-level security boundaries and identity-based controls

Lateral Movement

Control: East-West Traffic Security

Mitigation: Inter-service communication controls would likely have constrained the attacker's ability to pivot between AI infrastructure components by enforcing strict east-west traffic policies between workloads and service endpoints

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Distributed security visibility would likely have detected anomalous communication patterns and constrained the attacker's ability to maintain persistent command channels across multicloud AI service deployments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained the attacker's ability to exfiltrate sensitive data and credentials by enforcing strict outbound access controls and data loss prevention mechanisms

Impact (Mitigations)

Service disruption would likely have been contained to specific AI workload segments rather than affecting the entire infrastructure, with compromised LLM provider access limited to segmented network boundaries

Impact at a Glance

Affected Business Functions

  • AI Model Gateway Services
  • LLM Provider Integration
  • API Key Management
  • Machine Learning Operations
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $75,000

Data Exposure

API keys for multiple LLM providers including OpenAI, Anthropic, and other AI services. Potential exposure of gateway configuration data, authentication tokens, and AI model usage patterns. Risk of lateral movement through compromised credentials to connected AI services.

Recommended Actions

  • • Implement Zero Trust segmentation to isolate AI gateway components and prevent lateral movement across AI infrastructure using identity-based policies and least privilege access controls
  • • Deploy egress security and policy enforcement to monitor and control outbound traffic from AI gateways, preventing unauthorized data exfiltration and command & control communications
  • • Enable multicloud visibility and control to detect anomalous interactions with AI services, repeated malformed requests, and suspicious automation patterns that could indicate compromise
  • • Implement inline IPS with signature-based detection to identify and block known exploit patterns and malicious payloads targeting AI gateway vulnerabilities before they reach critical systems
  • • Deploy cloud native security fabric controls for real-time inspection and autonomous threat response to AI-specific risks including shadow AI usage and prompt injection attacks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image