Newly Disclosed Vulnerability in Amazon Bedrock AgentCore Raises Concerns About Credential Theft
The cybersecurity landscape has recently been shaken by the revelation of a new attack vector, known as AgentCorruption, that targets Amazon’s Bedrock AgentCore. This newly disclosed attack chain has raised significant concerns, as it can potentially turn a single malicious prompt into a pathway for credential theft and the compromise of other AI agents operating within the same AWS account and region.
Understanding AgentCorruption
Research into this vulnerability reveals a direct correlation between metadata access and an excessively privileged execution role. This linkage allows for lateral movement within systems, exposure of sensitive conversations, memory poisoning, and the theft of credentials associated with connected services. At its core, AgentCore operates containerized agents utilizing Firecracker microVMs, a mechanism designed to enhance security by isolating workloads.
The researchers provided compelling evidence demonstrating that an exposed agent outfitted with HTTP or shell tools could be manipulated into contacting the local metadata endpoint, specifically the address 169.254.169.254. This incident creates a server-side request forgery scenario that could lead to the compromise of sensitive metadata—specifically, temporary credentials for the agent’s execution role.
Mechanism of Exploitation
Once the exposed agent sends requests to this metadata endpoint, it returns critical credentials, including an access key ID, secret access key, and session token. With these credentials, researchers were able to export them to their own machines, subsequently verifying the assumed identity through AWS Security Token Service. Notably, this exploitation proceeded without requiring any further interaction with the compromised agent itself.
According to AWS documentation, this data retrieval mechanism is classified as the MicroVM Metadata Service (MMDS). It primarily indicates that any code or entity operating within the VM has the ability to access the execution-role credentials, thereby making the security ramifications heavily reliant on the permissions that are assigned to that role.
Default Security Concerns
According to analysis conducted by Zenity, the default execution role assigned to these agents encompassed permissions that extended far beyond just the compromised agent itself. Attackers could leverage commands like logs:DescribeLogGroups to uncover agent identifiers and subsequently invoke other runtimes utilizing the bedrock-agentcore:InvokeAgentRuntime command. Furthermore, broad permissions associated with the Amazon Elastic Container Registry also allowed attackers to obtain container images belonging to other agents, further jeopardizing sensitive application code and any hardcoded secrets.
The potential for memory permissions to exacerbate the situation cannot be overlooked. Researchers were able to enumerate memory resources, actors, and session details. By employing the command bedrock-agentcore:ListEvents, they could even retrieve stored conversations. This level of access, combined with write and delete permissions, enabled attackers to manipulate ongoing sessions, thereby injecting their own content and influencing the decision-making capabilities of the agent.
Long-Term Threats and Mitigations
The research indicates that these capabilities present a persistent threat, as long-term memories could be poisoned, and credentials could be harvested using commands like bedrock-agentcore:GetResourceApiKey and secretsmanager:GetSecretValue. Such vulnerabilities jeopardize authentication for associated services rather than directly exposing the agents themselves, amplifying the risk across interconnected tools.
Zenity’s disclosure timeline highlights that AWS implemented an IMDSv2-only policy for new agent deployments starting February 14, 2026. The company also noted substantial restrictions on execution roles on September 29, which included the removal of permissions that permitted broad agent invocation, conversation access, and Secrets Manager retrieval.
In response to the threat posed by AgentCorruption, AWS has acknowledged that access to execution-role metadata is a documented and expected behavior. The company emphasizes that cross-account access necessitates explicit authorization and recommends adopting a least privilege approach. This involves ensuring that execution roles do not possess privileges exceeding those required by the invoking users.
Final Thoughts
AgentCorruption serves as a crucial reminder of the heightened risk associated with prompt-driven tool execution in cloud environments. As the complexity of such systems increases, the necessity for tightly scoped IAM permissions becomes ever more critical. If left unchecked, a single compromised agent could lead to a cascade of failures, escalating to a serious breach of sensitive resources across numerous workloads. Organizations utilizing these cloud platforms must prioritize security measures that contain any compromises before they can propagate further, safeguarding both their data and their users effectively.
