
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4269 is an improper S3 ownership verification vulnerability in the Amazon Bedrock AgentCore Starter Toolkit that may allow a remote actor to inject code during the build process, leading to arbitrary code execution in the AgentCore Runtime. It affects all versions of the bedrock-agentcore-starter-toolkit Python package before v0.1.13, but only impacts users who built the toolkit after September 24, 2025. The vulnerability was disclosed on March 16, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 5.8 (Medium) (AWS Security Bulletin, Github Advisory).
The root cause is a missing verification of S3 bucket ownership (CWE-283: Unverified Ownership) combined with the use of predictable S3 identifiers (CWE-340: Generation of Predictable Numbers or Identifiers). Because the toolkit did not confirm that the S3 bucket used during the build process was owned by the expected AWS account, a remote attacker who could claim or control a predictably named S3 bucket could place malicious artifacts there. When a user triggered a build after September 24, 2025, the toolkit would fetch and incorporate these attacker-controlled artifacts, resulting in code execution within the AgentCore Runtime. The fix, introduced in v0.1.13 via pull request #194, adds explicit S3 bucket ownership verification to prevent this substitution attack (Github Advisory, GitHub Release v0.1.13).
Successful exploitation results in a complete loss of confidentiality, integrity, and availability of the affected AgentCore resource, as attacker-controlled code executes within the AgentCore Runtime environment. This could enable data theft, unauthorized access to AWS resources accessible by the runtime, and disruption of AI agent workloads. The impact is scoped to the subsequent system (the AgentCore Runtime) rather than the build host itself, but the runtime environment may have access to sensitive data and AWS IAM permissions that could facilitate further lateral movement (Github Advisory, AWS Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.047–0.068%, placing it in the 21st percentile for exploitation likelihood within 30 days. Exploitation requires high attack complexity (the attacker must successfully claim or control a predictably named S3 bucket) and passive user interaction (a build must be triggered). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory).
bedrock-agentcore-starter-toolkit Python package in versions prior to v0.1.13 that are actively building the toolkit after September 24, 2025.GetObject, ListBucket) to S3 buckets not owned by the expected AWS account ID.GetObject requests to buckets with unexpected owner account IDs during toolkit build operations; build logs referencing S3 bucket names not provisioned by the organization.sts:GetCallerIdentity, iam:ListRoles) that may indicate post-exploitation enumeration.AWS recommends upgrading to bedrock-agentcore-starter-toolkit version v0.1.13 or later immediately, which adds S3 bucket ownership verification to the build process (pip install bedrock-agentcore-starter-toolkit==0.1.13). Users who built the toolkit before September 24, 2025, or who are already on v0.1.13 or higher, are not affected and do not need to take action. No configuration-based workaround is available; upgrading is the only remediation. Organizations should also review S3 bucket access controls and verify that build-related S3 buckets are owned by the expected AWS account (AWS Security Bulletin, GitHub Release v0.1.13).
The vulnerability received moderate attention in the security community upon disclosure on March 16, 2026, with coverage appearing on Mastodon security feeds, infosec.exchange, and vulnerability tracking platforms shortly after publication. The AWS security team published a formal bulletin (2026-008-AWS) and coordinated disclosure through GitHub Advisories. No notable independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."