cvedb.io
CVE-2026-18830
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2026-08-04T18:16:49.420 · Last modified 2026-08-04T19:16:45.433

Summary

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.