CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-106032: bedrock-agentcore-starter-toolkit 0.1.4 through 0.3.13

CVE-2026-106032. CVSS 3.1 base score 5.7 (MEDIUM, Source advisory).

Affected technology

bedrock-agentcore-starter-toolkit · 0.1.4 through 0.3.13
aws

Description’s affected range: before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests and read arbitrary local files

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · Active user interaction

What an attacker can do

Source advisory’s CVSS 4.0 assessment (base score 5.7/10) rates confidentiality impact as high; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-918
CCR priority
22.8 /100 (P4)
CVSS 3.1
5.7 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-106032.html