CVE-2026-16584
Awaiting Analysis
Awaiting Analysis - Queue
Security Policy Bypass in AWS API MCP Server
Vulnerability report for CVE-2026-16584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-23
Last updated on: 2026-07-23
Assigner: AMZN
Description
Description
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected.
To remediate this issue, users should upgrade to version 1.3.47.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| awslabs | aws-api-mcp-server | From 0.2.13 (inc) to 1.3.47 (exc) |
| awslabs | aws-api-mcp-server | From 1.3.46 (inc) to 1.3.47 (exc) |
| awslabs | aws-api-mcp-server | 1.3.47 |
| aws | api_mcp_server | From 0.2.13 (inc) to 1.3.46 (inc) |
| aws | api_mcp_server | 1.3.47 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-455 | The product does not exit or otherwise modify its operation when security-relevant errors occur during initialization, such as when a configuration file has a format error or a hardware security module (HSM) cannot be activated, which can cause the product to execute in a less secure fashion than intended by the administrator. |