CVE-2026-18830: Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security contr
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18830
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18830 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Insufficient input validation
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validationaws · 2026-08-04
- unknownCVE-2026-15314: Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the ha…nvd · 2026-08-04
- highCVE-2026-16843: Some Hikvision Networking Products are vulnerable to authenticated command execution due to in…nvd · 2026-07-31
- mediumCVE-2026-18014: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72…nvd · 2026-07-30
- mediumCVE-2026-18009: Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.7…nvd · 2026-07-30
- criticalCVE-2026-18002: Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922…nvd · 2026-07-30
More from NVD Recent CVEs
- unknownCVE-2026-70474: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70473: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70472: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…2026-08-04
- unknownCVE-2026-70471: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- mediumCVE-2026-69704: Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate databas…2026-08-04