Vulnerability  ·  2026-09-11

AWS Security Agent / MCP server — missing S3 bucket ownership check exposes scanned-workspace source archives (credentials, infra state)

VulnerabilityMedium impactGlobalCVE-2026-87912
Two related AWS-published bulletins describe the same root cause — missing S3 bucket-ownership verification — in both the DevSecOps Security Agent plugin and its MCP server counterpart, allowing an attacker who pre-registers a specific bucket name to receive the source archive of any workspace scanned by a vulnerable instance.
AI-driven security-scanning agents are being widely adopted for automated vulnerability triage; a flaw that silently exfiltrates full source-code archives (including embedded secrets) to an attacker-controlled bucket undermines the trust model of exactly the tooling meant to improve security posture.
A missing S3 bucket-ownership verification check allows a remote attacker to pre-register a storage bucket that the tool subsequently writes scanned workspace archives to, exposing the private source archive — including any embedded credentials and infrastructure state — of any workspace scanned by an affected instance.
aws-agents-for-devsecops AWS Security Agent plugin, versions before 1.1.0; AWS Security Agent MCP server, versions before 0.2.0
Upgrade aws-agents-for-devsecops to 1.1.0+ and the AWS Security Agent MCP server to 0.2.0+; verify S3 bucket ownership is validated before write in any custom integration. AWS Security Bulletin 2026-105.
AWS Security Bulletin 2026-105NVD - CVE-2026-87912
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →