PT-2026-64006 · Amazon · Aws Api Mcp Server
CVE-2026-16584
·
Published
2026-07-23
·
Updated
2026-09-11
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AWS API MCP Server versions 0.2.13 through 1.3.46
Description
Improper handling of an initialization failure during server startup allows an actor to bypass the user-configured security policy. If the data used to enforce the security policy fails to load, the per-request policy check is silently skipped for the lifetime of the process. This allows the execution of AWS API operations that the policy was intended to deny or gate. The scope of this issue is limited to the security-policy gate, as IAM permissions on the configured credentials remain in effect and continue to restrict the server's capabilities.
Recommendations
Upgrade to version 1.3.47.
Use least-privilege IAM credentials scoped to the task.
Restart the server if it was started during degraded connectivity to ensure policy enforcement data loads successfully.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Api Mcp Server