CVE-2026-18830: AWS Bedrock AgentCore Tool Bypass
🟠 High | Source: AWS Security Bulletins A vulnerability in Amazon Bedrock’s AgentCore InvokeHarness API allowed authenticated users to trigger configured tools directly, bypassing the AI model and its associated security controls. The flaw meant that a crafted request containing a tool-use content block could cause the agent to dispatch tools without model mediation. AWS patched the issue on 31 July 2026; the blast radius was bounded by whichever tools were configured on the affected harness. ...