← Back to search

CVE-2026-18830

8.1 HIGH

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows an authenticated user to bypass security controls by crafting specific content in conversation messages, potentially executing unauthorized tools.
Exploitability
Exploitation requires authentication and knowledge of crafted content blocks, making it moderately difficult but feasible for advanced attackers.
Blast radius
If exploited, the impact could be significant as it allows execution of unauthorized tools bypassing model invocation and security measures within the system.
Prioritized remediation
Ensure all systems using Amazon Bedrock AgentCore are updated to the latest version to mitigate this vulnerability.
auth-bypassrcesecurity-controltool-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-1287

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.