CVE-2026-90898
- CVSS
- —
- EPSS
- 0.006 (47.5th percentile)
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage

The Hacker News
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all…
What we observed
No signals recorded