Code Injection Vulnerability in Bedrock AgentCore Starter Toolkit by AWS
CVE-2026-4269

5.8MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
16 March 2026

What is CVE-2026-4269?

A vulnerability in Bedrock AgentCore Starter Toolkit prior to version v0.1.13 allows remote attackers to exploit a missing S3 ownership verification. This could enable code injection during the build process, ultimately leading to arbitrary code execution within the AgentCore Runtime. Users should ensure they upgrade to version v0.1.13 or higher to safeguard against this potential risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Bedrock AgentCore Starter Toolkit 0.1.0 < 0.1.13

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.