Description
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.



To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Published: 2026-09-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to source archives and credentials
Action: Patch Immediately
AI Analysis

Impact

A missing verification of the ownership of an S3 bucket in the AWS Security Agent MCP server before version 0.2.0 permits an attacker to read the private source archive of a scanned workspace. The archive contains credentials and infrastructure state, which could be exfiltrated by the attacker.

Affected Systems

The vulnerability affects the AWS Security Agent MCP server, specifically all releases prior to 0.2.0.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited. Attackers can target a pre‑registered storage bucket whose name is derived from a publicly known account identifier, thereby obtaining confidential data. While the risk is moderate, the potential for exposing sensitive assets warrants prompt remediation.

Generated by OpenCVE AI on September 10, 2026 at 17:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AWS Security Agent MCP server to version 0.2.0 or later.
  • Verify that owned by your own AWS account, not by a third party.
  • Review and adjust IAM permissions to limit which users can register bucket names for scans.

Generated by OpenCVE AI on September 10, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:00:00 +0000


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Title Missing S3 bucket ownership verification in the AWS Security Agent MCP server
First Time appeared Aws
Aws aws Security Agent Mcp Server
Weaknesses CWE-283
CWE-341
CPEs cpe:2.3:a:aws:aws_security_agent_mcp_server:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Security Agent Mcp Server
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Aws Aws Security Agent Mcp Server
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-10T16:29:49.389Z

Reserved: 2026-09-09T15:23:10.427Z

Link: CVE-2026-87913

cve-icon Vulnrichment

Updated: 2026-09-10T16:28:15.783Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:18:07.187

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-87913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:30:10Z

Weaknesses
  • CWE-283

    Unverified Ownership

  • CWE-341

    Predictable from Observable State