CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15643

highCVSS 7.3covered by 2 sourcesfirst seen 2026-07-14
Bulletin ID: 2026-054-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:00 PM PDT Description: AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. We identified CVE-2026-15643, a server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Impacted versions: < 0.0.14 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

What
A server-side request forgery vulnerability allows authenticated users to exfiltrate AWS temporary security credentials.
Who is affected
Authenticated users of AWS HealthLake MCP Server versions prior to 0.0.14 are affected.
Urgency
This vulnerability is important and requires attention, though it is not actively exploited.
Action
Users should upgrade to version 0.0.14 or later to mitigate this issue.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15643

Get an email if CVE-2026-15643 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-15643

CVE.org record

Embed the live status

CVE-2026-15643 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15643 status](https://www.csirts.com/badge/CVE-2026-15643)](https://www.csirts.com/cve/CVE-2026-15643)