One prompt could get access to all AgentCore agents in one AWS account
Zenity says that AWS removed the wide permissions. AWS says that access of an agent to its execution role credentials is expected.
Claimed, not confirmed
Researchers at Zenity Labs found a risk in Amazon Bedrock AgentCore. One prompt sent to a public agent could give access to each agent in the same AWS account and region. The attack, named AgentCorruption, gave the researchers access to private chats, source code, memories, and secrets. Zenity says that AWS removed the permissions that made this possible. AWS disputes that this is a vulnerability.
How it worked
Zenity says that a prompt could tell an agent to contact the local metadata endpoint at 169.254.169.254. This endpoint gives temporary credentials to cloud workloads. This contact came from the microVM of the agent. Because of this, the endpoint gave back the credentials of the execution role.
What was exposed
Zenity says that the default role was for more than one agent. With it, the researchers could:
- find agents and operate internal agents
- read chats and session events
- make incorrect memories
- read keys and secrets in Secrets Manager
A hidden instruction in memory could change the goals of an agent in subsequent conversations.
Fix and dispute
Zenity reported the metadata access to AWS on December 25, 2025. On September 29, it confirmed that AWS removed the wide permissions. AWS says that an agent can get the credentials of its execution role through the metadata endpoint. AWS says that this is expected and documented.
What to do
AWS recommends roles with only the tasks and resources that each agent must have. Teams can also do these tasks:
- do not use wide wildcard permissions
- limit outbound network access
- keep public agents and internal agents isolated
- monitor CloudTrail and CloudWatch for unusual calls
This is a brief. We point to the report and do not rewrite it. Read it at the source below.
Sources
- One Prompt Could Hijack AWS AI Agents and Steal Cloud CredentialsCyberSecurityNews
Posted