AI
Published 2026-10-08
Verified 2026-10-10

AgentCorruption: one prompt to a public Amazon Bedrock AgentCore agent pulled its metadata credentials, and an over-broad default role let Zenity Labs reach every AgentCore agent in the account and region — chats, memories, source code and Secrets Manager values; AWS has tightened defaults

Zenity Labs disclosed AgentCorruption on 8 October 2026 at SecTor in Toronto. Researchers sent one prompt to a public-facing Amazon Bedrock AgentCore agent that had a common tool able to make outbound web requests, telling it to call the instance metadata service from inside its microVM. That returned temporary credentials for the agent's default execution role, and the role was not scoped to that agent: it carried region-wide AgentCore permissions. With it the researchers found other agents' IDs through CloudWatch log groups, pulled their container images (and source code) from ECR, invoked internal agents they were never meant to reach (bedrock-agentcore:InvokeAgentRuntime), read private conversations across agents and sessions (ListEvents), planted memories that redirected agents to send future conversations to an attacker (CreateEvent on AgentCore Memory), and read API keys, OAuth tokens and secrets (GetResourceApiKey, secretsmanager:GetSecretValue). Zenity reported the metadata access to AWS on 25 December 2025 and the role scope on 12 January 2026. AWS made IMDSv2 (MMDSv2) the default for new AgentCore runtimes and cut the default execution role's permissions; Zenity confirmed by 29 September that agent-to-agent invocation, chat reading and Secrets Manager access had been removed, and says the issues are fixed. AWS, per Cyber Security News, disputes calling it a vulnerability: it says an agent reaching its own execution-role credentials is expected and documented, and its guidance warns that any code inside the microVM can call the metadata endpoint. Existing agents built with the older broad default roles may still carry them. No in-the-wild abuse reported. Primary: Zenity press release and Zenity Labs write-ups; wire: Cyber Security News 10 Oct.

Product
Amazon Bedrock AgentCore (Runtime, Memory, Identity) — agents with built-in web or shell tools
Versions
AgentCore runtimes deployed with the earlier default execution role and IMDSv1 access; AWS has since changed defaults for new deployments
Exploited in Australia?
unknown
Patch to
No customer patch. Replace any CLI-generated or default AgentCore execution role with a custom role scoped to the single agent's runtime, memory and secrets ARNs (no runtime/* or region-wide wildcards); confirm IMDSv2/MMDSv2 is required on existing runtimes; limit agent outbound network access and block 169.254.169.254 from tools where you can; keep public and internal agents in separate accounts; review CloudTrail for InvokeAgentRuntime, ListEvents, CreateEvent, GetResourceApiKey and GetSecretValue calls from agent roles; review long-term memory for planted instructions.

Primary: Zenity — Zenity Labs discloses AgentCorruption, a chain of AWS AgentCore flaws (8 Oct 2026) · Vendor: AWS — Security best practices for AgentCore Runtime (least-privilege execution roles, gateway in front of runtimes) · Zenity Labs — AgentCorruption: how a single prompt collapsed the entire cloud security model (technical write-up)

ai cloud identity