SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-15415

MEDIUM · CVSS 5.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

AWS HealthOmics MCP Server versions prior to 0.0.36 are vulnerable to a directory traversal attack, allowing an unauthorized actor to write files to arbitrary locations outside the designated workflow bundle directory. This could lead to potential data manipulation or unauthorized access to sensitive information, impacting organizations utilizing this service for bioinformatics analyses. Users of AWS HealthOmics should prioritize upgrading to version 0.0.36 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15415
Severity
MEDIUM
CVSS
5.5
EPSS
0.25%

Original NVD Description

AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools of the AWS HealthOmics MCP Server (aws-healthomics-mcp-server) before version 0.0.36 might allow an actor who can influence the MCP agent to write an actor-controlled content to arbitrary locations outside the intended workflow bundle directory, via directory traversal sequences in the workflow_files input. To remediate this issue, users should upgrade to version 0.0.36 or later.