CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655, an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions: <= 2.0.23 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AI Analysis
Technical Summary
AWS Labs Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before version 2.0.24 contains an improper restriction of intended endpoints vulnerability in its RabbitMQ broker connection tools. This flaw allows a remote unauthenticated actor to exploit crafted broker hostnames introduced in the MCP client context to capture Amazon MQ RabbitMQ broker credentials or OAuth access tokens sent to attacker-controlled endpoints. The vulnerability affects all versions up to and including 2.0.23. AWS has addressed this issue in version 2.0.24 and recommends upgrading and rotating broker credentials. A temporary workaround is to disable auto-approve for the rabbimq_broker_initialize_connection and rabbimq_broker_initialize_connection_with_oauth tools to enforce manual inspection of broker hostnames.
Potential Impact
A remote unauthenticated attacker can obtain sensitive RabbitMQ broker credentials or OAuth access tokens by exploiting the improper endpoint restrictions in the affected versions of the Amazon MQ MCP Server. This could lead to unauthorized access to Amazon MQ brokers and potentially compromise message broker operations or data confidentiality. The impact is significant because it involves credential and token disclosure without authentication.
Mitigation Recommendations
An official fix is available in awslabs.amazon-mq-mcp-server version 2.0.24. Users should upgrade to this version promptly and rotate any broker credentials that may have been exposed. As a temporary mitigation before upgrading, disable auto-approve for the rabbimq_broker_initialize_connection and rabbimq_broker_initialize_connection_with_oauth tools to require manual verification of broker hostnames, rejecting any that do not match the expected Amazon MQ endpoint pattern.
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Description
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655, an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions: <= 2.0.23 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected software
pkg:github/aws-labs/amazon-mq-mcp-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AWS Labs Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before version 2.0.24 contains an improper restriction of intended endpoints vulnerability in its RabbitMQ broker connection tools. This flaw allows a remote unauthenticated actor to exploit crafted broker hostnames introduced in the MCP client context to capture Amazon MQ RabbitMQ broker credentials or OAuth access tokens sent to attacker-controlled endpoints. The vulnerability affects all versions up to and including 2.0.23. AWS has addressed this issue in version 2.0.24 and recommends upgrading and rotating broker credentials. A temporary workaround is to disable auto-approve for the rabbimq_broker_initialize_connection and rabbimq_broker_initialize_connection_with_oauth tools to enforce manual inspection of broker hostnames.
Potential Impact
A remote unauthenticated attacker can obtain sensitive RabbitMQ broker credentials or OAuth access tokens by exploiting the improper endpoint restrictions in the affected versions of the Amazon MQ MCP Server. This could lead to unauthorized access to Amazon MQ brokers and potentially compromise message broker operations or data confidentiality. The impact is significant because it involves credential and token disclosure without authentication.
Mitigation Recommendations
An official fix is available in awslabs.amazon-mq-mcp-server version 2.0.24. Users should upgrade to this version promptly and rotate any broker credentials that may have been exposed. As a temporary mitigation before upgrading, disable auto-approve for the rabbimq_broker_initialize_connection and rabbimq_broker_initialize_connection_with_oauth tools to require manual verification of broker hostnames, rejecting any that do not match the expected Amazon MQ endpoint pattern.
Technical Details
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-070-aws/","fetched":true,"fetchedAt":"2026-08-03T19:15:42.155Z","wordCount":233}
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a70e8debf32cb7a340dd633
Added to database: 08/03/2026, 19:15:42 UTC
Last enriched: 08/17/2026, 22:30:56 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 89
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.