CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent MCP server
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.
To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS Security Agent MCP serverto a version that resolves this vulnerability.Fixed in 0.2.0 - Configuration
Verify the scan output S3 bucket in your account is owned by your own account, because upgrading does not release a bucket name that a third party has already registered.
AWS account scan output S3 bucket bucket ownership = Verify owned by your own AWS account
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of AWS Security Agent MCP server versions before 0.2.0 may be exposed if the scan output bucket name derived from their publicly known account identifier was pre-registered by a third party. The affected archive may contain private source code, credentials, and infrastructure state.
What does an attacker need to exploit it?
An attacker needs to pre-register the storage bucket whose name is derived from the target account's publicly known identifier. Exploitation can then expose the scanned workspace archive to the attacker.
Are upgrades sufficient if a malicious bucket already exists?
No. Upgrading to version 0.2.0 is required, but it does not release a bucket name that a third party has already registered. Verify that the scan output bucket in your account is owned by your own account.
How can I determine whether my environment may already be affected?
Check the ownership of the scan output bucket used by the AWS Security Agent MCP server. If it is not owned by your account, scanned workspace archives may have been exposed.