Full Report
Tokens transmitted in metadata, weak VM isolation, and expansive permissions make hacking a lot easier
Analysis Summary
# Vulnerability: Amazon Bedrock AgentCore SSRF and Cross-Agent Lateral Movement
## CVE Details
- **CVE ID**: Not specified in the report (Internal AWS tracking/Zenity disclosure).
- **CVSS Score**: Not provided (Estimated: **9.1 - 9.9 Critical** based on unauthorized access to cross-tenant data and resource takeover).
- **CWE**:
- CWE-918: Server-Side Request Forgery (SSRF)
- CWE-266: Incorrect Privilege Assignment (Overpermissioned IAM)
- CWE-665: Improper Initialization (Weak VM isolation)
## Affected Systems
- **Products**: Amazon Bedrock AgentCore
- **Versions**: All versions deployed prior to February 14, 2026 (for IMDS issue) and June 22, 2026 (for IAM permission issue).
- **Configurations**: Agents running on Firecracker MicroVMs utilizing Instance Metadata Service version 1 (IMDSv1) with default IAM role assignments.
## Vulnerability Description
The vulnerability stems from a triple-failure in the AgentCore security model:
1. **Network Isolation Failure**: The Firecracker MicroVMs hosting the agents failed to block access to the Instance Metadata Service (IMDS) endpoint.
2. **SSRF via Prompt Injection**: Attackers could use natural language prompts to trick the agent into fetching data from the internal IMDSv1 endpoint (`http://169.254.169.254`).
3. **Expansive IAM Scoping**: The temporary credentials fetched from IMDS were not limited to the specific agent instance. Instead, the default IAM role was scoped to *all* AgentCore resources within the entire AWS region for that account.
## Exploitation
- **Status**: PoC available (Demonstrated by Zenity Labs).
- **Complexity**: Low (Requires only basic prompt engineering/chat access).
- **Attack Vector**: Network (Remote via AI Chat Interface).
## Impact
- **Confidentiality**: **High**. Attackers can enumerate all agents, pull container images from ECR, read user session histories, and extract secrets from AWS Secrets Manager.
- **Integrity**: **High**. Attackers can create or modify "memories" across different agents, persistently altering agent behavior and hijacking goals for future sessions.
- **Availability**: **High**. Unauthorized access allows for the launching or manipulation of regional agent resources.
## Remediation
### Patches
- **AWS Bedrock AgentCore Update (Feb 14, 2026)**: Enforced IMDSv2 exclusively, which requires a session header that agents cannot easily spoof via simple URL fetching.
- **IAM Policy Revision (Late Sept 2026)**: AWS remediated the overprivileged default roles to ensure session/agent isolation.
### Workarounds
- **Manual Policy Review**: Users should ensure any IAM roles assigned to Bedrock agents follow the principle of least privilege, specifically limiting `Resource` ARNs to individual agents rather than wildcards (`*`).
- **Disable IMDS**: Where possible in cloud environments, disable IMDS or strictly enforce IMDSv2 with a hop limit of 1 to prevent SSRF traversal.
## Detection
- **Indicators of Compromise**:
- Unusual API calls to `ecr:BatchGetImage` or `ecr:GetDownloadUrlForLayer` from AgentCore service roles.
- Unexpected calls to `bedrock:ListAgents` or `bedrock:GetAgentMemory` originating from temporary agent credentials.
- Prompt logs containing requests for internal IP addresses or the `169.254.169.254` address.
- **Detection Methods**: CloudTrail log analysis for credential usage outside of the expected micro-service boundary.
## References
- Zenity Labs Research: hxxps[://]labs[.]zenity[.]io/post/agentcorruption-how-a-single-prompt-collapsed-the-entire-cloud-security-model
- AWS IMDSv2 Documentation: hxxps[://]docs[.]aws[.]amazon[.]com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service[.]html
- Video Demonstration: hxxps[://]www[.]youtube[.]com/watch?v=Q2IwwO6djTU