← Back to the feed

Exposed AgentCore agents leaked credentials, enabling wider AWS access

The Register ·

Researchers at Zenity Labs found that a prompt sent to an exposed Amazon Bedrock AgentCore agent could retrieve temporary AWS credentials, potentially giving an attacker access to other agents and their data. The findings highlight how weak network isolation and overly broad permissions can turn access to one AI agent into a wider cloud security risk.

The researchers said AgentCore agents could reach the Instance Metadata Service and, at the time, used IMDSv1. Credentials obtained this way let them enumerate agents, inspect container images and access agent sessions, while broad IAM permissions also allowed changes to agent memories that could affect later behaviour. AWS switched AgentCore to IMDSv2 by 14 February 2026; Zenity reported that the excessive permissions persisted in June, but found the issues had been addressed by 29 September.

  • A prompt could expose an AgentCore agent’s temporary AWS credentials.
  • Broad permissions put other agents and user sessions at risk.
  • Zenity said AWS had addressed the reported issues by September 2026.

New here? Start with this

Amazon Bedrock AgentCore is a cloud service that allows organisations to run AI agents. When these agents are exposed to the internet without proper security controls, they become vulnerable to attack.

Researchers discovered that an exposed agent could leak temporary access credentials for Amazon's cloud infrastructure. An attacker with these credentials could potentially access other agents, view their data, and make changes that affect their future behaviour.

The vulnerability reveals a broader cloud security challenge: weak isolation and overly broad permissions can turn access to one system into a springboard for much wider compromise. This is particularly concerning for organisations deploying AI services who may not fully understand the associated security risks.

Cybersecurity Technology

Read the full article at the source →

Originally published by The Register as “AWS AgentCore security undone by prompt requesting credentials”.