{"id":"CVE-2026-18830","published":"2026-08-04T18:16:49.420","lastModified":"2026-08-06T15:46:36.880","description":"Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-1287"],"vendors":[],"products":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-073-aws/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an authenticated user to bypass security controls by crafting specific content in conversation messages, potentially executing unauthorized tools.","exploitability":"Exploitation requires authentication and knowledge of crafted content blocks, making it moderately difficult but feasible for advanced attackers.","blast_radius":"If exploited, the impact could be significant as it allows execution of unauthorized tools bypassing model invocation and security measures within the system.","remediation":"Ensure all systems using Amazon Bedrock AgentCore are updated to the latest version to mitigate this vulnerability.","tags":["auth-bypass","rce","security-control","tool-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:49:51.136Z"}}