Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected.
To remediate this issue, users should upgrade to version 1.3.47.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users should upgrade to version 1.3.47. | |
| Title | AWS API MCP Server Security Policy Bypass via Startup Failure | |
| First Time appeared |
Aws
Aws aws-api-mcp-server |
|
| Weaknesses | CWE-455 | |
| CPEs | cpe:2.3:a:aws:aws-api-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-api-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-23T18:16:50.894Z
Reserved: 2026-07-22T13:43:35.240Z
Link: CVE-2026-16584
No data.
No data.
No data.
OpenCVE Enrichment
No data.