PT-2026-25792 · Unknown · Agentcore Runtime+1
Published
2026-03-16
·
Updated
2026-05-11
·
CVE-2026-4269
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bedrock AgentCore Starter Toolkit versions prior to v0.1.13
Description
A missing S3 ownership verification may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build the Toolkit after September 24, 2025. Successful exploitation could result in a complete loss of confidentiality, integrity, and availability of the affected AgentCore resource. The issue involves improper S3 ownership verification.
Recommendations
Upgrade to version v0.1.13.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agentcore Runtime
Bedrock Agentcore Starter Toolkit