Amazon Bedrock AgentCore Security Flaw Lets Users Bypass AI Safety Guards
Amazon Bedrock AgentCore's InvokeHarness API has a nasty input validation bug (CVE-2026-18830) that lets authenticated users trigger configured tools without the AI model checking them first. If your harness has tools set up, attackers could invoke them directly, skipping all those safety controls you've got in place. The good news? Impact is limited to whatever tools you've actually configured—empty harnesses are safe. You'll want to update immediately if you're running versions before July 31, 2026.