Amazon MQ MCP Server RabbitMQ Connector Endpoint Bypass <=2.0.24
CVE-2026-18655 Published on August 3, 2026
Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
To remediate this issue, users should upgrade to version 2.0.24.
Vulnerability Analysis
CVE-2026-18655 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Restriction of Communication Channel to Intended Endpoints
The software establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
Products Associated with CVE-2026-18655
stack.watch emails you whenever new vulnerabilities are published in Aws Amazon Mq Mcp Server or Amazon Aws. Just hit a watch button to start following.
Affected Versions
AWS amazon-mq-mcp-server:- Before and including 2.0.23 is affected.