‘AgentCorruption’ Puts AWS Environments At Risk With Single Prompt

A newly patched vulnerability in AWS Bedrock AgentCore has left organizations with a potentially devastating cybersecurity risk. Dubbed “AgentCorruption,” this flaw allows an attacker to use just one AI chatbot to take control of an entire fleet of agents within an AWS environment, effectively gaining access to sensitive data and wreaking havoc on the organization’s cloud infrastructure.

The vulnerability was discovered by researchers at Zenity Labs, who demonstrated its potency during a recent presentation at SecTor 2026 in Toronto. According to Tamir Ishay Sharbat, director of security research at Zenity, the issue lies with the Instance Metadata Services (IMDS) within Bedrock AgentCore. IMDS contains sensitive information such as temporary credentials, instance IDs, and configurations, which are meant to be accessible only by authorized agents. However, in this case, an attacker can exploit a weakness in the way these services are configured to access this data.

Sharbat noted that IMDS has been a vulnerability in cloud environments since their inception, citing the 2019 Capital One data breach as a prime example. In that incident, attackers used a Server-Side Request Forgery (SSRF) flaw to access EC2 instance metadata and subsequently retrieve sensitive data. What sets AgentCorruption apart is its use of public-facing agents to perform these requests, rather than exploiting an SSRF vulnerability directly.

In a demonstration of the attack’s potential, Sharbat showed how his team could send a request to IMDS via a support agent, granting them temporary credentials that allowed them to access additional agents and even secrets stored in AWS’s Secrets Manager. This is made possible by the fact that agents deployed through Bedrock AgentCore run within Firecracker MicroVMs, which lack sufficient network isolation.

The implications of this vulnerability are far-reaching, as an attacker could use a single prompt to an over-privileged public-facing agent to compromise an entire region. The researchers also demonstrated how they could engage in memory poisoning attacks against the agents, further exacerbating the damage.

To mitigate these risks, AWS has taken steps to address the issue by updating AgentCore to use IMDSv2, which requires authentication, and altering the default role’s permissions to limit its access. However, organizations should remain vigilant and take proactive measures to secure their cloud environments, including implementing strict access controls and following the principle of least privilege (POLP).

Ultimately, the discovery of AgentCorruption serves as a stark reminder of the inherent conflicts between cloud computing and AI, which often prioritize flexibility over security. By understanding these risks and taking steps to address them, organizations can better protect themselves against emerging threats like this one.


Source: Dark Reading — 2026-10-08