Bifrost CVE-2026-90898: unauth MCP client registration is RCE
JFrog found that Bifrost HTTP transport before 2.1.0 accepts an unauthenticated POST to /api/mcp/client and immediately starts the given stdio command as the gateway user when management auth is off (the default). Patch is transports/v2.1.0; rotate provider keys if the management API was exposed.