PT-2026-64006 · Amazon · Aws Api Mcp Server

CVE-2026-16584

·

Published

2026-07-23

·

Updated

2026-09-11

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AWS API MCP Server versions 0.2.13 through 1.3.46
Description Improper handling of an initialization failure during server startup allows an actor to bypass the user-configured security policy. If the data used to enforce the security policy fails to load, the per-request policy check is silently skipped for the lifetime of the process. This allows the execution of AWS API operations that the policy was intended to deny or gate. The scope of this issue is limited to the security-policy gate, as IAM permissions on the configured credentials remain in effect and continue to restrict the server's capabilities.
Recommendations Upgrade to version 1.3.47. Use least-privilege IAM credentials scoped to the task. Restart the server if it was started during degraded connectivity to ensure policy enforcement data loads successfully.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16584
GHSA-29W2-FQ35-V728
PYSEC-2026-3549

Affected Products

Aws Api Mcp Server