CVE-2026-4270 - AWS API MCP File Access Restriction Bypass
Bulletin ID: 2026-007-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 09:15 AM PDT Description: The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. This server acts as a bridge between AI assistants and AWS services, allowing you to create, update, and manage AWS resources across all available services. The server includes a configurable file access feature that controls how AWS CLI commands interact with the local file system. By default, file operations are restricted to a designated working directory (workdir), but this can be configured to allow unrestricted file system access (unrestricted) or to block all local file path arguments entirely (no-access). We identified CVE-2026-4270: Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. Impacted versions: awslabs.aws-api-mcp-server >= 0.2.14, < 1.3.9 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- A file access restriction bypass could allow unrestricted file system access.
- Who is affected
- Users of the AWS API MCP Server.
- Urgency
- Remediation is important to maintain proper security controls.
- Action
- Review and configure file access settings appropriately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AWS API MCP Server
Get an email when a new AWS API MCP Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-007-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-42700.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-4270 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - AWS API
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-16640: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd · 2026-08-25
- unknownCVE-2026-38470: A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall…nvd · 2026-08-25
- criticalCVE-2026-65083: NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an …nvd · 2026-08-25
- mediumGHSA-mf8r-wm2w-f8c5: phpMyFAQ public FAQ APIs expose inactive FAQ contentghsa · 2026-08-25
- highCVE-2026-24169: NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenti…nvd · 2026-08-25
- mediumCVE-2026-24168: NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated att…nvd · 2026-08-25
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20