{"data":{"id":"9c64b991-5ce0-42bc-8e78-27b04bec0a27","title":"CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation","summary":"A vulnerability (CVE-2026-18830) was found in Amazon Bedrock's AgentCore harness that allowed authenticated users to run configured tools without the AI model reviewing the request first, bypassing security controls. The issue only affected tools that were already set up on a given harness, so systems with no tools configured were not at risk.","solution":"Update Amazon Bedrock AgentCore harness InvokeHarness API to the version released after July 31, 2026.","labels":["security"],"sourceUrl":"https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/","publishedAt":"2026-08-04T17:45:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["Amazon Bedrock","Amazon Bedrock AgentCore"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-04T17:45:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","safety"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}