CVE-2026-18830
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
04/08/2026
Last modified:
06/08/2026
Description
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH


