AgentCorruption Flaw Could Expose AWS Bedrock AgentCore Environments to Takeover

Summary
Researchers found that a prompt to a public-facing Bedrock AgentCore agent could expose instance credentials and enable access to other agents and secrets in an AWS region. AWS updated IMDS settings and default permissions; researchers reported no known exploitation.
Key points
- Zenity researchers found AgentCore agents could access Instance Metadata Services (IMDS), which can provide temporary credentials and instance information.
- A single prompt to a public-facing agent with HTTP request capability could trigger an IMDS request and compromise that agent.
- Researchers said AgentCore's default role had broad regional permissions, enabling access to other agents, sessions, and AWS Secrets Manager secrets.
- The researchers also reported the potential for memory-poisoning attacks against agents.
- AWS updated AgentCore in February so newly deployed agents use authenticated IMDSv2 and restricted the default role's permissions.
- Zenity reported the issues to AWS beginning in December; researchers said they had no evidence of exploitation before the fixes.
Article Details
- Vulnerability Types
- Insufficient network isolation allowing agents to access the Instance Metadata Service
- Overly permissive default role
- Exploitation Status
- not_reported
- Exploit Availability
- unknown
- Patch Status
- available
- Workarounds
- Limit agent privileges to those required for the agent's specific role.
MITRE ATT&CK
People
Vendors
Products
AWS Secrets Managerallowed agents to invoke other agents, read private conversations, and access secrets stored in AWS Secrets Manager, among other restrictions.Bedrock AgentCoreof security research at AI security vendor Zenity Labs, who detailed a now-patched flaw in AWS Bedrock AgentCore during a session at SecTor 2026 on Wednesday. Bedrock AgentCore, which launched last year, is AWS'sFirecracker MicroVMThis is because, according to Zenity, an agent deployed through the AgentCore platform runs inside a Firecracker MicroVM, which doesn't have the necessary network isolation in place.