CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Cybersecurity Classified by Officially
CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
Bulletin ID: 2026-105-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/10/2026 08:30 AM PDT
AWS Security Agent is a managed AWS service that provides AI-powered code security reviews, threat modeling, and penetration testing.
We identified CVE-2026-87912, where a missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before version 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.
We identified CVE-2026-87913, where a missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.
This issues has been addressed in agent-toolkit-for-aws and awslabs.security-agent-mcp-server version 0.2.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Upgrading does not release a bucket name that a third party has already registered. We recommend that you verify the scan-input bucket security-agent-scans-<account-id>-<region> in your account is owned by your own account. As a precaution, you can pre-create that bucket in your own account before first use so that the predictable name cannot be registered by another account.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-105-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
a41ef7e97f89d1c93a812d41151217ad1b95348b