S3 Bucket Ownership Verification Issue in AWS Security Agent MCP Server
CVE-2026-87913
5.1MEDIUM
What is CVE-2026-87913?
A significant security vulnerability exists in the AWS Security Agent MCP Server prior to version 0.2.0, related to the lack of ownership verification for S3 buckets. This flaw can potentially allow remote attackers to access sensitive information, including private source archives containing credentials and the infrastructure state of scanned workspaces. This exposure arises when a pre-registered storage bucket's name is derived from a publicly known account identifier. To mitigate this risk, it is essential to upgrade to version 0.2.0 and ensure that the scan output bucket is owned by the account user to prevent exploitation by unauthorized entities.
Affected Version(s)
AWS Security Agent MCP server 0.1.0 <= 0.1.5
