Zenity researchers expose flaw compromising AWS AgentCore AI agents
Zenity Researchers Expose Cloud Flaws in Amazon Bedrock AgentCore
Researchers at Zenity Labs demonstrated that a single prompt sent to one publicly reachable AI agent on Amazon Bedrock AgentCore could compromise every AgentCore agent residing within the same AWS account and region, according to a technical disclosure published on October 8, 2026. The vulnerability chain, designated as AgentCorruption, permitted external actors to extract private conversations, clone source code, steal sensitive credentials, and alter long-term agent memory. Amazon Bedrock AgentCore functions as a managed platform enabling enterprises to build, orchestrate, and deploy autonomous AI agents equipped with external tools and persistent storage.
The Tech TL;DR:
- The Exploit Vector: A single malicious prompt directed at one public-facing agent utilizing standard web tools allowed researchers to query the internal metadata service and harvest temporary AWS security credentials.
- The Blast Radius: Because AgentCore’s default execution roles applied permissions across an entire account and region, compromised credentials granted unauthorized access to every deployed agent container image, internal API key, and user session.
- The Remediation Status: AWS updated newly deployed AgentCore agents to enforce IMDSv2 by default starting in February 2026 and systematically restricted overly permissive default execution roles by late September 2026.
Exploiting Metadata Services via Unrestricted Agent Tools
The attack initiated through a standard agent configuration equipped with basic web request capabilities. The research team utilized a test agent built via the open-source Strands framework, which incorporates tools such as HTTP requests and shell command execution. When researchers instructed the agent in plain natural language to fetch data from the local instance metadata service at 169.254.169.254, the virtual machine running the workload fulfilled the request without network isolation barriers. According to technical write-ups, this initial server-side request forgery bypass surfaced because AgentCore lacked the strict sandbox boundaries traditionally enforced on standard cloud infrastructure workloads. The metadata endpoint returned temporary AWS Security Token Service (STS) credentials, including access keys, secret keys, and active session tokens.
curl -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" -X PUT "http://169.254.169.254/latest/api/token"
curl -H "X: " http://169.254.169.254/latest/meta-data/iam/security-credentials/
Escalation Across Regional Agent Infrastructure
Stolen credentials acquired from the initial metadata extraction enabled the researchers to operate completely outside the conversational interface. As reported by Zenity Labs, the core systemic weakness involved the default execution role assigned by AgentCore, which spanned across entire AWS accounts and regions rather than remaining strictly scoped to individual agent instances. Michael Bargury, Zenity co-founder and chief technology officer, stated in the primary research publication that cloud security fundamentals rely heavily on least-privilege access and resource segmentation, noting that AI agent platforms require operational creative space that frequently creates conflicts with traditional boundary enforcement. Utilizing the harvested administrative privileges, the research team enumerated all active agents in the region, downloaded container images and underlying source code packages from Amazon Elastic Container Registry, and invoked internal agents that should have remained entirely isolated from external traffic.
Persistent Compromise Through Long-Term Memory Poisoning
The exploitation vector extended beyond instantaneous data theft into persistent infrastructure manipulation by targeting agent memory systems. Zenity Labs detailed how write access to agent long-term memory allowed researchers to inject fabricated conversation events that stored lasting instructions within the platform. These injected prompts commanded affected agents to query an external web server controlled by the researchers prior to generating responses for legitimate users. By dynamically updating the external target page, attackers could alter agent operational parameters continuously without deploying new memory blocks. This mechanism allowed malicious interception of ongoing chats, enabling automated forwarding of sensitive user interactions directly to external servers while maintaining normal interface functionality for unsuspecting end users.
AWS Closes Metadata Report After Transitioning to IMDSv2
Coordinated vulnerability disclosure between Zenity Labs and Amazon Web Services spanned multiple months across late 2025 and 2026. Zenity reported the underlying metadata access vulnerability to AWS on December 25, 2025, and subsequently highlighted the broad default execution roles on January 12, 2026. AWS initially closed the metadata report as informative in April 2026, noting that newly deployed AgentCore instances had transitioned to enforce IMDSv2 requirements—which mandate session tokens for metadata queries—starting February 14, 2026. However, broad default execution permissions remained active through June 2026. A final verification check conducted by Zenity on September 29, 2026, confirmed that AWS had ultimately revoked permissions allowing inter-agent invocation, private conversation reading, and unauthorized access to AWS Secrets Manager, while narrowing remaining operational privileges ahead of public disclosure at the SecTor 2026 conference.
Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only. Always consult with certified IT and cybersecurity professionals before altering enterprise networks or handling sensitive data.