On October 9, 2026, Zenity said its reported Amazon Bedrock AgentCore issue affected agents in the same AWS account and region, did not cross an account boundary, and had been fully mitigated. Amazon Web Services (AWS), which operates AgentCore, disputed the description of the research as demonstrating a vulnerability.
Zenity limits its reported AgentCore finding to one AWS account and region
Zenity’s statement put the demonstration within a single AWS account and region. It also said the reported issue had been fully mitigated. AWS’s response said the research inaccurately characterized expected and documented behavior as a vulnerability; it did not affirm Zenity’s account of mitigation.
How the reported metadata-and-permissions chain worked
In Zenity’s test, a Strands-based agent with an HTTP request tool was prompted to contact 169.254.169.254, the runtime’s metadata endpoint, and relay the response. Zenity said the response contained temporary AWS STS credentials tied to the agent’s execution role—the set of permissions assigned to that runtime—and that its researchers used those credentials outside AgentCore. Zenity also said it reproduced metadata access with a shell tool.
The role permissions mattered to the reported chain. In the configuration Zenity tested, the default role had broad regional permissions involving AgentCore runtimes, container images in Amazon ECR, and AgentCore Memory. Zenity said those permissions made the credentials useful beyond the agent that obtained them.
What Zenity says those permissions exposed
Zenity reported that, within the same AWS account and region, the tested permissions let its researchers enumerate and invoke other agents, retrieve agent images, read private conversation events, and alter memory or session events. These were reported results from Zenity’s test configuration.
Zenity said a review on September 29, 2026, found substantial changes to the default execution role, including removal of permissions for cross-agent invocation, private-conversation access, and Secrets Manager access, with other permissions also restricted. On October 9, Zenity said the reported issue had been fully mitigated.
AWS’s documented credential model and least-privilege advice
AWS’s AgentCore security guidance says code or actors running inside an AgentCore microVM can access execution-role credentials through the MicroVM Metadata Service (MMDS). The guidance recommends narrowly scoped roles and custom policies limited to the actions and resources an agent needs. It says CLI-generated IAM policies are intended for development and testing, not production.
AWS says access to resources in another AWS account requires explicit permission on both the agent’s execution role and the target resource. Its documentation also requires MMDSv2 for runtimes starting June 30, 2026; runtimes without it cannot be invoked.