S3 Bucket Ownership Verification Issue in AWS Security Agent MCP Server
CVE-2026-87913

5.1MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
10 September 2026

What is CVE-2026-87913?

A significant security vulnerability exists in the AWS Security Agent MCP Server prior to version 0.2.0, related to the lack of ownership verification for S3 buckets. This flaw can potentially allow remote attackers to access sensitive information, including private source archives containing credentials and the infrastructure state of scanned workspaces. This exposure arises when a pre-registered storage bucket's name is derived from a publicly known account identifier. To mitigate this risk, it is essential to upgrade to version 0.2.0 and ensure that the scan output bucket is owned by the account user to prevent exploitation by unauthorized entities.

Affected Version(s)

AWS Security Agent MCP server 0.1.0 <= 0.1.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

glow.io
.