Skip to content
Vulnerabilities in AWS Bedrock AgentCore Expose AI Agents to Hijacking

Vulnerabilities in AWS Bedrock AgentCore Expose AI Agents to Hijacking

First seen 8 Oct 2026, 15:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 16:42 UTC
  • •A single prompt can hijack all AI agents in an AWS account due to critical vulnerabilities.
  • •AWS has released partial fixes, but the vulnerabilities remain systemic and require manual intervention.
  • •The attack exploits over-permissive default roles and improper isolation in the AgentCore platform.

Researchers from Zenity Labs discovered a chain of vulnerabilities in Amazon's Bedrock AgentCore that allowed a single prompt to hijack all AI agents in an AWS account and region. The flaws stemmed from improper isolation and over-permissive default roles, enabling attackers to access sensitive data, including internal AWS credentials, source code, and private conversations. The vulnerabilities, termed 'AgentCorruption,' were exacerbated by the lack of session token enforcement in the microVM Metadata Service. AWS has implemented partial fixes, but experts recommend stricter manual role assignments for AI agents. The attack vector involved sending a simple chat message to a public agent, which then compromised other agents within the same AWS account. The researchers demonstrated that they could manipulate agent memory and access external services using stolen credentials. The issue affects organizations using AWS Bedrock AgentCore, which became globally available in late 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Vulnerabilities disclosed by Zenity Labs
Zenity Labs revealed critical flaws in AWS Bedrock AgentCore that allow hijacking of AI agents through a single prompt.
The-Decoder
2026-10-08
Partial fixes implemented by AWS
AWS announced partial fixes to tighten default permissions and improve metadata access controls in AgentCore.
The-Decoder

More articles in this cluster (6)

Following this threat?

Track AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What specific vulnerabilities were found?
The vulnerabilities include improper isolation and over-permissive default roles in AWS Bedrock AgentCore.
How can organizations protect themselves?
Organizations should manually assign stricter roles to their AI agents and monitor for suspicious activity.
Is there a patch available?
AWS has implemented partial fixes, but organizations are advised to take additional security measures.