Improper Endpoint Restriction in Amazon MQ MCP Server by AWS Labs
CVE-2026-18655

7.1HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
3 August 2026

What is CVE-2026-18655?

An improper restriction of intended endpoints in the Amazon MQ MCP Server prior to version 2.0.24 may expose sensitive information such as broker credentials or OAuth access tokens. This occurs when a remote unauthenticated actor exploits a prompt injection vulnerability, allowing access to crafted endpoints controlled via broker hostnames in the MCP client context. Users are urged to upgrade to version 2.0.24 to mitigate this risk.

Affected Version(s)

amazon-mq-mcp-server 0 <= 2.0.23

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.