LOWVulnerability
Global

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

·Source: AWS Security Bulletins

Updated:

Executive Summary

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation

Analysis

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Indicators of Compromise (1)

CVE (1)
CVE-2026-18830
Source Attribution

Originally published by AWS Security Bulletins on Aug 4, 2026.

Related Threats

CRITICALVulnerabilityNEW

Ruby on Rails critical bug puts every image upload under scrutiny

A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066 , could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails. Dubbed “KindaRails2Shell,” it targets the overly-trusting Acti

CVE-2026-66066
CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-18859 — A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an un...

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18859
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18854 — A vulnerability has been found in Shandong Hoteam PDM Product Data Management Sy...

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was

CVE-2026-18854
NIST NVD