CVE-2026-18830
Received Received - Intake

Amazon Bedrock AgentCore Input Validation Bypass

Vulnerability report for CVE-2026-18830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: AMZN

Description

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
amazon bedrock_agentcore_harness to 2026-07-31 (exc)
amazon bedrock_agentcore *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1287 The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient input validation in Amazon Bedrock AgentCore harness. An authenticated remote user could bypass model invocation and security controls by sending crafted content blocks in conversation messages. This allows direct execution of configured tools without the model's mediation process.

Detection Guidance

This vulnerability is specific to Amazon Bedrock AgentCore harness and does not require manual detection on your network. AWS has automatically applied server-side fixes. No customer action or commands are needed for detection.

Impact Analysis

The impact is limited to the tools configured on the harness. A harness with no tools cannot execute actions, while one with restricted tools is confined to that set. This could allow unauthorized execution of specific tools if the harness has them configured.

Compliance Impact

The vulnerability allows authenticated users to execute configured tools without model mediation, potentially bypassing security controls. This could lead to unauthorized data access or actions, which may violate compliance requirements for data protection standards like GDPR or HIPAA if sensitive data is involved. However, the impact is limited to the tools configured on the harness, reducing the scope of potential violations.

Mitigation Strategies

No immediate steps are required. AWS has already resolved the issue by implementing server-side input validation. Ensure your Amazon Bedrock AgentCore harness is updated to versions after July 31, 2026.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart