Vulnerability  ·  2026-04-12

aws-mcp-server Critical Command Injection (CVE-2026-5058)

VulnerabilityHigh impactCVE-2026-5058
Critical command injection vulnerability in aws-mcp-server allowing unauthenticated remote code execution via improper validation of user-supplied strings used in system calls. CVSS 9.8.
Unauthenticated remote exploitation via command injection into the server's allowed commands list handling. No authentication or specialised tooling required.
aws-mcp-server and any agentic AI system using it as an MCP endpoint for AWS CLI operations.
Patch immediately. Restrict network access to MCP server instances. Implement input validation on all user-supplied strings before system calls. Audit MCP server configurations for exposed endpoints.
Sources
TheHackerWire - CVE-2026-5058Tenable - CVE-2026-5058
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →