Threat
AWS AgentCore security undone by prompt requesting credentials
First reported theregister.com
Page published · Page updated
Earliest dated coverage: 9 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 9 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
The AgentCore flaw shows that a single indirect prompt to a deployed cloud AI agent can collapse the entire account's security model, extracting credentials and exfiltrating other users' conversations across all agents in a region.
Zenity Labs disclosed a flaw in Amazon Bedrock AgentCore where a single prompt could coax an exposed AI agent into fetching its own IMDS credential endpoint and returning temporary AWS credentials. Because the Firecracker MicroVM lacked sufficient network isolation and AgentCore used IMDSv1, an attacker with only chat access could extract those credentials, enumerate and take over all AgentCore agents in the same AWS account and region, pull container images, and read users' agent sessions and conversations. The findings were disclosed to AWS in December 2025.
Summary
Researchers at Zenity Labs disclosed a chain of weaknesses in Amazon Bedrock AgentCore that allowed an external attacker with nothing more than chat access to a single exposed agent to send one prompt, extract the agent's temporary IMDS credentials, and take over all AgentCore agents in the same AWS account and region. The core issues were AgentCore's use of IMDSv1, insufficient network isolation in its Firecracker MicroVM, and an overpermissioned default IAM role.[0]
Using the stolen credentials, an attacker could enumerate other agents, pull container images from Amazon ECR, read user sessions and conversations, persistently write malicious agent memories to hijack agent behaviour, and fetch secrets from AWS Secrets Manager. The scenario is illustrated through a hypothetical attacker named 'Bob' browsing a site hosting an AgentCore-served agent; no real-world in-the-wild exploitation is reported.[0]
Zenity disclosed the IMDS/SSRF issue in December 2025 and the overprivilege issue in January 2026. AWS moved AgentCore to IMDSv2 exclusively by February 14, 2026, but the excessive permissions remained until at least June 22, 2026; Zenity confirmed all issues were addressed by its final review on September 29, 2026.[0]
Attack chain
- Initial access via prompt injection / SSRF: An attacker with chat access to an exposed AgentCore agent asks the agent to fetch and return the raw JSON content of the Instance Metadata Service (IMDS) credential endpoint, abusing the agent as an SSRF vector enabled by weak Firecracker MicroVM network isolation and IMDSv1.[0]
- Credential theft: The IMDS response contains the agent's temporary AWS credentials for its assigned IAM role, which the attacker loads onto a local machine.[0]
- Enumeration and lateral movement: Because the default AgentCore role was scoped to all AgentCore resources in the region, the attacker enumerates other agents in the AWS region, logs into Amazon ECR, pulls agent container images, and runs them as root to inspect source code.[0]
- Data access and persistence: The attacker discovers memory resources in the region, extracts users' agent sessions and conversations, and issues direct API requests to create new memories across different agents and users, persistently altering agent behaviour and hijacking agent goals across future sessions; secrets can also be pulled from AWS Secrets Manager.[0]
Disclosure timeline
| Date | Event |
|---|---|
| December 2025 | Zenity Labs disclosed to AWS that AgentCore agents could access their IMDS endpoints and have credentials extracted via a single prompt.[0] |
| January 2026 | Zenity followed up with details that AgentCore's default role was overprivileged.[0] |
| February 14, 2026 | AWS updated AgentCore to use IMDSv2 exclusively.[0] |
| April 12, 2026 | AWS responded that the report was 'informative' and closed it, noting the IMDSv2 change.[0] |
| June 22, 2026 | Zenity checked in and found the excessive permissions issue had not been remediated.[0] |
| September 29, 2026 | Zenity's final review found AWS had addressed the remaining problems.[0] |
| October 9, 2026 | The Register published an account of the Zenity Labs findings.[0] |
How it works
AgentCore agents were able to reach their instance's IMDS endpoints because the Firecracker MicroVM used by AgentCore failed to provide sufficient network isolation, and AgentCore used IMDSv1. An attacker could direct the agent to perform a server-side request forgery (SSRF) attack by fetching temporary AWS credentials for the IAM role assigned to the workload directly from IMDS.[0]
The default AgentCore IAM role was overpermissioned, scoped to all AgentCore resources in the region rather than a single agent. Anyone holding the temporary IAM credentials could therefore launch other agents, read sessions, write agent memories, and fetch secrets from AWS Secrets Manager. Writing new memories via direct API requests allowed persistent alteration of agent behaviour and hijacking of agent goals across future sessions.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| Amazon Bedrock AgentCore | Deployments using IMDSv1 and the overpermissioned default role (observed late 2025 through mid-2026) | AgentCore moved to IMDSv2 exclusively as of February 14, 2026; remaining excessive-permission issues confirmed addressed by September 29, 2026.[0] |
Key takeaways
- A single prompt instructing an AI agent to fetch a metadata URL can escalate into full account- and region-level compromise when IMDSv1, weak VM isolation, and overpermissioned roles combine.[0]
- Agent memory is a persistence mechanism: attackers who can write memories can durably hijack agent goals across future sessions, not just exfiltrate a single conversation.[0]
- Patching one link in a chain is insufficient; AWS fixed IMDSv1 months before the overpermission issue, which remained exploitable until mid-to-late 2026.[0]
Defensive actions
- Enforce IMDSv2 exclusively for agent and workload instances.: AgentCore's use of IMDSv1 allowed agents to be coerced via prompt/SSRF into returning their temporary credentials; IMDSv2 addresses this class of credential-theft risk.[0]
- Scope agent IAM roles to the least privilege needed for a single agent rather than all AgentCore resources in a region.: The overpermissioned default role let a single stolen credential take over all AgentCore agents, read sessions, write memories, and fetch Secrets Manager secrets across the account and region.[0]
- Isolate agent workloads at the network level and restrict agents from fetching arbitrary internal URLs.: Insufficient Firecracker MicroVM network isolation enabled the SSRF path to IMDS; limiting agent-initiated requests to internal metadata endpoints mitigates the attack.[0]