CVE-2026-4269 describes a missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13, allowing a remote actor to inject code during the build process. This flaw specifically impacts toolkits built after September 24, 2025, potentially leading to code execution in the AgentCore Runtime. Rated 7.5 HIGH on the CVSS scale, the vulnerability has a network attack vector but requires high attack complexity and user interaction (AC:H/UI:R) to achieve high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog as actively exploited, it is on the "Hot List" indicating elevated risk, with no public exploit code currently available. Community discussion and media coverage are minimal, and affected users should upgrade to version v0.1.13 to remediate the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 0.1.13CPE match | cpe:2.3:a:amazon:bedrock_agentcore_starter_toolkit:*:*:*:*:*:python:*:* | ||
< 0.1.13CPE matchmatch criteria | cpe:2.3:a:amazon:bedrock_agentcore_starter_toolkit:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.