Unit 42: AWS AgentCore Harness default shell can expose Identity vault plaintext via prompt injection
Palo Alto Networks Unit 42 (Niv Rabin; published 18 September 2026) documents that default configurations of Amazon Web Services AgentCore Harness can let an attacker steer the agent via prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. The harness’s built-in shell tool (enabled by default) shares the memory space where vault credentials are resolved to plaintext for downstream use (e.g. authenticating to an MCP server). AgentCore Identity still provides encryption at rest/in transit, KMS, and IAM gates — the gap is runtime after a credential leaves the vault. Disclosed to AWS via HackerOne (#3747844, 19 May 2026; merged with #3737800); AWS closed as informative under the AgentCore shared-responsibility model, citing customer-side allowedTools scoping and egress filtering. Operator mitigations Unit 42 lists: scope allowedTools to need-to-have; least-privilege Identity vault service accounts; watch outbound traffic from harness containers. Watchlist: Palo Alto / AWS agentic AI stack. Primary: Unit 42.
- Product
- AWS AgentCore Harness + AgentCore Identity (default shell tool / MCP credential path)
- Versions
- n/a (default-config design/shared-responsibility finding; AWS closed informative — not a CVE)
- Exploited in Australia?
- unknown
- Patch to
- Scope AgentCore allowedTools (disable unused shell); least-privilege Identity vault accounts; egress filter harness containers; do not treat vault encryption-at-rest as runtime isolation from the agent shell.
Primary: Unit 42 — AgentCore Harness / Identity vault plaintext (18 Sep 2026) · Vendor: Palo Alto Networks Unit 42 (AWS disclosure via HackerOne; closed informative) · Unit 42 — disclosure timeline May–June 2026 / operator mitigations
