PT-2026-25792 · Unknown · Bedrock Agentcore Starter Toolkit+1
CVE-2026-4269
·
Publicado
2026-03-16
·
Atualizado
2026-07-13
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bedrock AgentCore Starter Toolkit versions prior to v0.1.13
Description
A missing S3 ownership verification may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build the Toolkit after September 24, 2025. Successful exploitation could result in a complete loss of confidentiality, integrity, and availability of the affected AgentCore resource. The issue involves improper S3 ownership verification.
Recommendations
Upgrade to version v0.1.13.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Agentcore Runtime
Bedrock Agentcore Starter Toolkit