CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18830 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from AWS Security Bulletins
- unknownCVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project D…2026-08-04
- unknownCVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools2026-08-03
- unknownCVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands2026-08-03
- unknownCVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Inje…2026-08-03
- unknownCVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool2026-07-31