AWS AgentCore security undone by prompt requesting credentials
Tokens transmitted in metadata, weak VM isolation, and expansive permissions make hacking a lot easier
Bob, a user browsing the TechHub site, utilized an AI agent served by Amazon Bedrock AgentCore to understand a credential endpoint. The endpoint returned data from Amazon's Instance Metadata Service (IMDS), which contains sensitive information like user data and security tokens. When AgentCore still used IMDSv1, Bob loaded the credentials onto his local machine and could enumerate and compromise the company's other agents in the AWS region.
Zenity Labs disclosed this security flaw to AWS in December 2025, who acknowledged the issue in a follow-up on January 2026. Despite being informed, AWS did not adequately remediate the problem until June 22, 2026, leaving the overprivileged permissions and vulnerabilities in place until September 29, 2026.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- AWS AgentCore security undone by prompt requesting credentials theregister.com