{"data":{"id":"f5069b43-8625-46f0-917d-b0af815df101","title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","summary":"Researchers found that AWS AgentCore Harness, a managed runtime for AI agents (software that can reason and take actions), has a security flaw where attackers can use prompt injection (tricking an AI by hiding instructions in its input) to steal plaintext credentials from the identity vault (secure storage for passwords and keys). The problem occurs because the harness's built-in shell tool, which is enabled by default and runs with root access (highest-level permissions), can access the same memory where credentials are temporarily exposed when retrieved from the vault.","solution":"AWS recommends a layered defense approach for operators: (1) \"Scope the allowedTools the harness can use to what it needs\"; (2) \"Scope Identity vault service accounts to least privilege for the downstream integration\"; and (3) \"Watch outbound traffic from your harness containers.\"","labels":["security"],"sourceUrl":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","publishedAt":"2026-09-18T10:00:36.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection"],"issueType":"news","affectedPackages":null,"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS","Amazon Web Services","AWS AgentCore Harness","AWS AgentCore Identity"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-18T10:00:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}