Amazon Bedrock AgentCore SDK flaws exposed AWS credentials
Two vulnerabilities in Amazon Bedrock AgentCore's Python SDK (CVE-2026-12530 and CVE-2026-16796) allowed command execution inside the Code Interpreter AI sandbox and access to temporary AWS credentials tied to the execution role. AWS fixed them in versions 1.6.1 and 1.18.1, scoring them 7.3 under CVSS 3.1 and 8.4 under CVSS 4.0.
- CVE-2026-12530 hit SDK 1.1.3–1.6.0 and was fixed in 1.6.1
- CVE-2026-16796 bypassed the first fix and was closed in 1.18.1
- Flaws scored 7.3 (CVSS 3.1) and 8.4 (CVSS 4.0)
- AWS advises upgrading to 1.18.1 and avoiding untrusted package names
Read next
Security