Description
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.



To remediate this issue, users should upgrade to version 2.0.24.
Published: 2026-08-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper restriction of intended RabbitMQ broker connection endpoints in the Amazon MQ MCP Server’s broker tools allows a remote, unauthenticated actor to inject a malicious prompt that creates a crafted endpoint. This abuse can lead to the disclosure of broker credentials or OAuth access tokens that are normally sent to a broker hostname. The exposed credentials may then enable full trust access to the RabbitMQ broker and any downstream services relying on these tokens, representing a significant confidentiality breach. The weakness is formally categorized as CWE‑923.

Affected Systems

All installations of AWS Amazon MQ MCP Server with versions older than 2.0.24 are affected. The vulnerability originates in the RabbitMQ broker connection utilities provided by the MCP Server and impacts any system that relies on these utilities for broker authentication.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating high severity, while its EPSS score is not available and it is not listed in CISA’s KEV catalog, suggesting no known active exploitation. A remote, unauthenticated attacker may exploit the flaw by injecting a prompt that causes the MCP client to target a user‑controlled hostname, thereby capturing broker credentials or OAuth tokens transmitted to that endpoint. The lack of authentication and insufficient endpoint restrictions amplify the risk of credential misuse once exposed.

Generated by OpenCVE AI on August 4, 2026 at 09:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Amazon MQ MCP Server to version 2.0.24 or later.
  • Disable any unused RabbitMQ broker endpoints and enforce strict endpoint validation so only expected hostnames can be contacted.
  • Implement network segmentation or access control lists that limit who can reach the MCP Server, and monitor for anomalous credential traffic or unauthorized connection attempts.

Generated by OpenCVE AI on August 4, 2026 at 09:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. To remediate this issue, users should upgrade to version 2.0.24.
Title Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
First Time appeared Aws
Aws amazon-mq-mcp-server
Weaknesses CWE-923
CPEs cpe:2.3:a:aws:amazon-mq-mcp-server:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws amazon-mq-mcp-server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aws Amazon-mq-mcp-server
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-03T19:52:25.587Z

Reserved: 2026-08-03T13:08:30.204Z

Link: CVE-2026-18655

cve-icon Vulnrichment

Updated: 2026-08-03T19:52:22.208Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T20:17:17.557

Modified: 2026-08-04T14:48:22.933

Link: CVE-2026-18655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:42Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints