bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-4270

show all
Thursday, August 20, 2026

AWS API MCP Server File Access Bypass – Update Required

AWS API MCP Server versions 0.2.14 through 1.3.9 have a nasty vulnerability (CVE-2026-4270) that lets attackers bypass file access restrictions and read arbitrary files on your system. The no-access and workdir protection modes are both affected—yeah, even the supposedly locked-down ones. If you're running this MCP server to let AI assistants talk to AWS, you need to upgrade to version 1.3.9 or later ASAP. This one requires immediate action.

source: [aws/security-bulletin]