CVE-2026-90898 | maximhq Bifrost up to 2.0.x MCP Client Registration /api/mcp/client access control
A vulnerability classified as critical was found in maximhq Bifrost up to 2.0.x. The affected element is an unknown function of the file /api/mcp/client of the component MCP Client Registration. Such manipulation leads to improper access controls.
This vulnerability is listed as CVE-2026-90898. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More