CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Summary
A vulnerability (CVE-2026-18830) was found in Amazon Bedrock's AgentCore harness that allowed authenticated users to run configured tools without the AI model reviewing the request first, bypassing security controls. The issue only affected tools that were already set up on a given harness, so systems with no tools configured were not at risk.
Solution / Mitigation
Update Amazon Bedrock AgentCore harness InvokeHarness API to the version released after July 31, 2026.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
First tracked: August 4, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%