Skip to main content
CybersecurityCloud Security

AWS AgentCore Flaw Exposes Credentials, Enables Lateral Attacks

Rows of computer servers and storage systems in a brightly-lit data center with a laptop in the foreground.

"We discovered that agents deployed through AgentCore could access their instance's IMDS endpoints," said Tamir Ishay Sharbat and Lana Salameh in a blog post. "This meant that an external attacker with nothing more than chat access to a single exposed agent could send a single prompt, extract its IMDS credentials, and use them to take over all AgentCore agents in the same AWS account and region."

How a chat prompt turned into stolen credentials

On a browsing session late last year, a user identified as Bob queried an AI agent hosted on a site called TechHub. The agent, an Amazon Bedrock AgentCore instance, was asked to fetch and present the contents of a URL — a credential endpoint — in raw JSON. The returned data came from the Instance Metadata Service (IMDS), the cloud-hosted metadata API that can include region, availability zone, injected public keys, user data and, crucially, temporary security tokens.

At that time AgentCore still used IMDSv1. The metadata returned to Bob contained the agent's temporary IAM credentials. Using those credentials, Bob remotely enumerated other AgentCore agents in the same AWS region, authenticated to the Amazon Elastic Container Registry (ECR), pulled agent container images, ran them as root to inspect source code, and extracted memory resources and user sessions.

Firecracker MicroVM network isolation failure

Zenity Labs' researchers identified the root technical failure as insufficient network isolation in the Firecracker MicroVM environment used by AgentCore. That lapse enabled a server‑side request forgery (SSRF) pattern: an attacker could instruct the agent to fetch the IMDS endpoint and expose the temporary AWS credentials assigned to the workload. Once obtained, those credentials were immediately useful.

What an attacker could do with the temporary IAM credentials

Zenity's report describes a rapid escalation chain. The default AgentCore role was overpermissioned — scoped to all AgentCore resources in the region rather than to a single agent. With the temporary credentials an attacker could:

  • launch new AgentCore agents in the region;
  • read existing agent sessions and extract stored conversations;
  • write or create new agent memories, altering agent behaviour across sessions;
  • fetch secrets from AWS Secrets Manager; and
  • pull container images from ECR and run them as root to inspect code and configuration.

“By leveraging the IMDS credentials we could send direct API requests to create new memories across different agents and users,” the researchers wrote. “These in turn would persistently alter agent behaviour and hijack the agents’ goals across future sessions.”

Zenity Labs' disclosure timeline and AWS' response

Zenity Labs disclosed their initial findings to AWS in December 2025. They followed up in January 2026 to report that AgentCore's default IAM role was overprivileged. AWS acknowledged the report on April 12, 2026, characterizing Zenity's submission as "informative" and closing the report. In that response AWS noted that, as of February 14, 2026, AgentCore had been updated to use IMDSv2 exclusively.

However, Zenity checked again on June 22, 2026 and found the excessive permissions issue had not been remediated. A final Zenity review on September 29, 2026 observed that AWS had addressed the remaining problems.

What this means for technologists and affected enterprises

Technologists and security teams now have a concrete case study tying together three elements: VM-level network isolation, metadata service access patterns (IMDSv1 versus IMDSv2), and IAM role scope. In this incident the combination allowed an attacker with only chat access to an exposed agent to obtain credentials that could be used to move laterally across agents in the same account and region.

Affected enterprises and procurement leaders should note two specifics in the record: first, that AgentCore instances initially relied on IMDSv1 and therefore remained susceptible to simple metadata‑fetch patterns; and second, that the default AgentCore IAM role was scoped broadly enough to permit cross-agent actions, including reading and writing agent memories and accessing Secrets Manager.

Final observation

The vulnerability chain established by Zenity Labs ties a small interaction — a single prompt delivered to an AI agent — to systemic risk across a cloud account: SSRF to IMDS, temporary IAM tokens, and an overpermissioned role that allows region-wide agent control. AWS moved AgentCore to IMDSv2 by February 14, 2026 and later addressed the permissioning concerns, but the timeline shows a gap between technical mitigation and full privilege hardening. That interval is exactly where Zenity's hypothetical "Bob" was able to demonstrate exfiltration, enumeration and persistence. The record ends with AWS having addressed the problems as of September 29, 2026; the practical lesson is explicit in the researchers' testing: microVM isolation, metadata access controls and least-privilege IAM are all required to prevent a chat message from becoming a full account compromise.

Original story