Bedrock AgentCore Flaw Lets Authenticated Remote Users Execute Tools
CVE-2026-18830 Published on August 4, 2026

Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-18830 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

Improper Validation of Specified Type of Input

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.


Products Associated with CVE-2026-18830

stack.watch emails you whenever new vulnerabilities are published in Aws Amazon Bedrock Agentcore Harness or Amazon Aws. Just hit a watch button to start following.

 
 

Affected Versions

AWS Amazon Bedrock AgentCore harness Version N/A is affected by CVE-2026-18830