CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-18830: AWS Bedrock AgentCore Tool-Use Injection

August 6, 2026

Insufficient input validation in Amazon Bedrock AgentCore's InvokeHarness API allows authenticated remote users to inject tool-use blocks that bypass model invocation, leading to unauthorized tool execution. CVSS v4.0 score 8.6. Fixed by AWS on July 31, 2026.