{
  "id": 772609,
  "title": "The Server Was Up. Its Security Policy Wasn’t.",
  "url": "https://urgent.news/2026/08/13/the-server-was-up-its-security-policy-wasnt",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-13T14:08:48.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/lav_vishwakarma/the-server-was-up-its-security-policy-wasnt-2kej"
  },
  "original_language": "en",
  "account": "On July 23, 2026, AWS released a security advisory regarding a vulnerability (CVE-2026-16584) in the AWS API MCP Server, which I had reported. The advisory rated the issue as High, with a CVSS v4.0 score of 7.3. I was acknowledged as the independent researcher who discovered the flaw.\n\nThe short version of the issue is that the server could start, even if the data required to enforce its security policy could not be loaded. Once that happened, the policy check was skipped for the lifetime of the process. The server was running, but the security policy wasn't.\n\nThe Model Context Protocol (MCP) enables AI assistants to connect with tools and external systems, and the AWS API MCP Server lets an assistant interact with AWS services through AWS CLI commands. The server includes an optional, user-configured security policy to deny or gate selected AWS operations before execution.\n\nThe problem occurred during the process of loading the data needed to enforce the set policy. If this initialization failed, the process could continue running without the enforcement data. When a request arrived, the policy check could be bypassed, allowing operations to proceed even if the security policy was not in place.\n\nThis vulnerability does not bypass AWS IAM permissions, but it reduces the effective risk depending on the scope of the credentials used. This incident highlights the importance of least privilege in AWS IAM, not only to prevent unintended users from doing too much but also to limit damage when another security layer fails unexpectedly. The MCP server's role as a boundary between an AI agent's intent and real infrastructure underscores the need for robust security controls, as missing policy enforcement could lead to permissive behavior.",
  "summary": "What CVE-2026-16584 in the AWS API MCP Server taught me about MCP security, fail-open systems, and the controls we place between AI agents and real infrastructure. On July 23, 2026, AWS published a security advisory for a vulnerability I reported in the AWS API MCP Server. It was assigned CVE-2026-16584 , rated High, and given a CVSS v4.0 score of 7.3. My name appears in the acknowledgement as…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}