CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent MCP server

Published Sep 10, 2026
·
Updated

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.

To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.

Affected Software

1 affected component
Amazon Web Services AWS Security Agent MCP server<0.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AWS Security Agent MCP server to a version that resolves this vulnerability.

    Fixed in 0.2.0
  2. Configuration

    Verify the scan output S3 bucket in your account is owned by your own account, because upgrading does not release a bucket name that a third party has already registered.

    AWS account scan output S3 bucket bucket ownership = Verify owned by your own AWS account

Event History

Sep 10, 2026
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users of AWS Security Agent MCP server versions before 0.2.0 may be exposed if the scan output bucket name derived from their publicly known account identifier was pre-registered by a third party. The affected archive may contain private source code, credentials, and infrastructure state.

2

What does an attacker need to exploit it?

An attacker needs to pre-register the storage bucket whose name is derived from the target account's publicly known identifier. Exploitation can then expose the scanned workspace archive to the attacker.

3

Are upgrades sufficient if a malicious bucket already exists?

No. Upgrading to version 0.2.0 is required, but it does not release a bucket name that a third party has already registered. Verify that the scan output bucket in your account is owned by your own account.

4

How can I determine whether my environment may already be affected?

Check the ownership of the scan output bucket used by the AWS Security Agent MCP server. If it is not owned by your account, scanned workspace archives may have been exposed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203