AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18830

HIGH · CVSS 8.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Amazon Bedrock's AgentCore harness is vulnerable due to insufficient input validation, allowing authenticated remote users to execute tools by bypassing security controls through specially crafted conversation messages. This could lead to unauthorized actions within the system, posing a significant risk to data integrity and security. Organizations utilizing Amazon Bedrock should prioritize monitoring for any unusual activity, although no immediate action is required as AWS has already addressed the vulnerability.

CVE
CVE-2026-18830
Severity
HIGH
CVSS
8.1
EPSS
0.29%

Original NVD Description

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.