CVE-2026-18830: CWE-1287 Improper validation of specified type of input in AWS Amazon Bedrock AgentCore harness
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
AI Analysis
Technical Summary
This vulnerability (CWE-1287) in the Amazon Bedrock AgentCore harness stems from improper validation of input types. An authenticated remote user could exploit this flaw by crafting content blocks within conversation messages to execute configured tools, circumventing the intended model invocation and security controls. AWS manages the remediation for this cloud-hosted service and has fixed the issue as per their security bulletin.
Potential Impact
Successful exploitation could lead to unauthorized execution of configured tools by an authenticated user, resulting in high confidentiality and integrity impact. Availability is not affected. The vulnerability enables bypassing of security controls designed to restrict tool execution within the service.
Mitigation Recommendations
AWS has addressed this vulnerability in their cloud service environment. Since this is a cloud-hosted service, AWS manages the remediation server-side. According to the vendor advisory, no customer action is required.
CVE-2026-18830: CWE-1287 Improper validation of specified type of input in AWS Amazon Bedrock AgentCore harness
Description
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CVSS v3.1
Score 8.1high
Affected software
AWS
Amazon Bedrock AgentCore harness
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-1287) in the Amazon Bedrock AgentCore harness stems from improper validation of input types. An authenticated remote user could exploit this flaw by crafting content blocks within conversation messages to execute configured tools, circumventing the intended model invocation and security controls. AWS manages the remediation for this cloud-hosted service and has fixed the issue as per their security bulletin.
Potential Impact
Successful exploitation could lead to unauthorized execution of configured tools by an authenticated user, resulting in high confidentiality and integrity impact. Availability is not affected. The vulnerability enables bypassing of security controls designed to restrict tool execution within the service.
Mitigation Recommendations
AWS has addressed this vulnerability in their cloud service environment. Since this is a cloud-hosted service, AWS manages the remediation server-side. According to the vendor advisory, no customer action is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- AMZN
- Date Reserved
- 2026-08-04T14:11:16.899Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://aws.amazon.com/security/security-bulletins/2026-073-aws/","vendor":"AWS"}]
Threat ID: 6a7227ffbf8831d53935a8d4
Added to database: 08/04/2026, 17:57:19 UTC
Last enriched: 08/11/2026, 18:09:15 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 123
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.