CVE-2026-18830

AWS · Amazon Bedrock AgentCore

Amazon Bedrock AgentCore contains an input validation vulnerability that allows authenticated users to bypass security controls and execute tools via crafted conversation messages.

Executive summary

A vulnerability in Amazon Bedrock AgentCore allows authenticated users to bypass security controls and potentially perform unauthorized code execution via crafted inputs.

Vulnerability

The vulnerability stems from insufficient input validation in the AgentCore harness. This allows an authenticated user to inject crafted content blocks that bypass model invocation controls, enabling the execution of configured tools.

Business impact

With a CVSS score of 8.1, this vulnerability presents a high risk of unauthorized tool execution and potential data exfiltration. The ability to perform outbound DNS queries, even within a sandbox environment, allows for command-and-control communication, which could lead to significant data breaches or unauthorized infrastructure manipulation.

Remediation

Immediate Action: Apply the latest vendor security updates provided by AWS in their security bulletin.

Proactive Monitoring: Audit logs for the Amazon Bedrock AgentCore for unusual tool invocation patterns or unexpected outbound network traffic from the code interpreter environment.

Compensating Controls: Review and restrict the permissions and tool definitions assigned to Bedrock Agents to minimize the impact of potential unauthorized executions.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Organizations utilizing Amazon Bedrock AgentCore should review the official AWS security bulletin and apply the recommended updates immediately. Given the potential for covert command-and-control channels, monitoring for suspicious outbound activity in sandbox environments is highly recommended.