Threat · curated 8 Aug 2026

CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

Coverage timeline

8 Aug 2026amazon.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-18655 shows how indirect prompt injection against an MCP server can exfiltrate broker credentials and OAuth tokens, giving attackers a path to authenticated access through the AI tool-calling layer.

CVE-2026-18655 is a vulnerability in the AWS Labs Amazon MQ MCP Server where prompt injection can cause disclosure of broker credentials and OAuth tokens. AWS published security bulletin 2026-070-AWS marking it as Important (requires attention), with a corresponding GitHub security advisory (GHSA-xwj6-8x5h-hjp6).