AWS API MCP Server 0.2.13-1.3.46 Init Failure Bypass
CVE-2026-16584 Published on July 23, 2026
AWS API MCP Server Security Policy Bypass via Startup Failure
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected.
To remediate this issue, users should upgrade to version 1.3.47.
Vulnerability Analysis
CVE-2026-16584 is exploitable with local system access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Non-exit on Failed Initialization
The software does not exit or otherwise modify its operation when security-relevant errors occur during initialization, such as when a configuration file has a format error, which can cause the software to execute in a less secure fashion than intended by the administrator.
Products Associated with CVE-2026-16584
stack.watch emails you whenever new vulnerabilities are published in Aws Api Mcp Server or Amazon Aws. Just hit a watch button to start following.
Affected Versions
aws-api-mcp-server:- Version 0.2.13 and below 1.3.47 is affected.