CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness โ Insufficient Input Validation
Amazon Bedrock ยท 2026-09-09
Actions
Technical Details
| Affected Versions | prior to July 31, 2026 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18830 |
| Cost Impact | Neutral |
What This Means
For DevOps Teams
Update the Amazon Bedrock AgentCore harness to the latest version to incorporate the server-side input validation that prevents bypassing security controls.
For Platform Teams
Deploy the updated Amazon Bedrock AgentCore harness with enhanced input validation to ensure secure and reliable tool execution.
For Executives
Implement the security patch for Amazon Bedrock AgentCore harness to mitigate the risk of bypassing security controls and ensure the integrity of configured tools.
Source
Related Amazon Bedrock Updates
- OpenAI GPT-6 Astra is now generally available on Amazon Bedrock (2026-09-08)
- Web Search on Amazon Bedrock is now available in AWS GovCloud (US-West) (2026-09-02)
- Introducing Claude Fable 5.1 on AWS (2026-09-01)
- AWS Agent Registry for centralized agent discovery and governance is now generally available (2026-08-31)
- SpaceXAI Grok 4.6 now available on Amazon Bedrock in AWS GovCloud (US) (2026-08-28)