Initialization Failure in AWS API MCP Server Allows Bypassing Security Policies
CVE-2026-16584
7.3HIGH
What is CVE-2026-16584?
An improper handling of initialization failures in AWS API MCP Server versions 0.2.13 to 1.3.46 allows potential attackers to bypass user-configured security policies and perform AWS API operations that would normally be denied. This issue occurs when the enforcement of security policy initialization fails during server startup, leading to skipped policy checks for the life of the process. While IAM permissions remain intact, the vulnerability poses significant risks as it can enable unauthorized API access. Users are advised to upgrade to version 1.3.47 to mitigate this vulnerability.
Affected Version(s)
aws-api-mcp-server 0.2.13 < 1.3.47
