CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

Mq Mcp ยท 2026-08-20

Actions

Rate this issue

Technical Details

Affected Versions <= 2.0.23
Regions all
CVE IDs CVE-2026-18655
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update awslabs.amazon-mq-mcp-server to version 2.0.24 and rotate broker credentials to address CVE-2026-18655, ensuring that your deployments are secure from potential credential and token disclosure vulnerabilities.

For Platform Teams

Deploy the latest version of awslabs.amazon-mq-mcp-server and integrate credential rotation practices to enhance the security posture of your message broker environment.

For Executives

Implement the upgrade to awslabs.amazon-mq-mcp-server version 2.0.24 to mitigate the risk of broker credential and OAuth token disclosure, ensuring the security and integrity of your message broker interactions.

Source

View original AWS announcement โ†’

Related Mq Mcp Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.