CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Insufficient input validation in InvokeHarness API allows authenticated users to execute tools bypassing model invocation and security controls.
- Who is affected
- Authenticated users of Amazon Bedrock AgentCore InvokeHarness API prior to July 31, 2026.
- Urgency
- High; authenticated bypass of security controls allows tool execution without intended model mediation.
- Action
- Update Amazon Bedrock AgentCore to the version released on or after July 31, 2026.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Amazon Bedrock AgentCore
Get an email when a new Amazon Bedrock AgentCore advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-188300.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18830 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from AWS Security Bulletins
- unknownCVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Syste…2026-09-10
- unknownCVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library2026-09-10
- unknownCVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK2026-09-09
- highCVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit2026-09-09
- unknownCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server2026-09-09