Threat · curated 8 Aug 2026
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
First reported amazon.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-18655 shows how indirect prompt injection against an MCP server can exfiltrate broker credentials and OAuth tokens, giving attackers a path to authenticated access through the AI tool-calling layer.
CVE-2026-18655 is a vulnerability in the AWS Labs Amazon MQ MCP Server where prompt injection can cause disclosure of broker credentials and OAuth tokens. AWS published security bulletin 2026-070-AWS marking it as Important (requires attention), with a corresponding GitHub security advisory (GHSA-xwj6-8x5h-hjp6).