CVE-2026-18830
8.1 HIGHPublished 2026-08-04 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw allows an authenticated user to bypass security controls by crafting specific content in conversation messages, potentially executing unauthorized tools.
- Exploitability
- Exploitation requires authentication and knowledge of crafted content blocks, making it moderately difficult but feasible for advanced attackers.
- Blast radius
- If exploited, the impact could be significant as it allows execution of unauthorized tools bypassing model invocation and security measures within the system.
- Prioritized remediation
- Ensure all systems using Amazon Bedrock AgentCore are updated to the latest version to mitigate this vulnerability.
auth-bypassrcesecurity-controltool-execution
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-1287
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.