CVE-2026-18830
Last modified
CVE-2026-18830 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AWS | Amazon Bedrock AgentCore harness | N/A |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-18830?
How severe is CVE-2026-18830?
How do I fix CVE-2026-18830?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18821IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.3…8.8
- CVE-2026-18822IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …5.5
- CVE-2026-18823Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-18824IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …8.8
- CVE-2026-18828IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …7.5
- CVE-2026-1883The Wicked Folders – Folder Organizer for Pages, Posts, and …4.3
- CVE-2026-18832IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.8
- CVE-2026-18835IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.9
- CVE-2026-18839An integer underflow was found in the popt library when form…2.2
- CVE-2026-1884A weakness has been identified in ZenTao up to 21.7.6-85642.…4.9
- CVE-2026-18840IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …7.8
- CVE-2026-18842IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …7.8
Are you affected by CVE-2026-18830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
