Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-4269

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected. To remediate this issue, customers should upgrade to version v0.1.13.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-4269


Contact Us

Shodan ® - All rights reserved