Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-4269

7.5 · HIGH
Published Mar 16, 2026 amazon CWE-283

Overview

CVE-2026-4269 is a high-severity vulnerability affecting amazon bedrock_agentcore_starter_toolkit. It was published on March 16, 2026 and has a CVSS 3.1 base score of 7.5 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected.

To remediate this issue, customers should upgrade to version v0.1.13.

Remediation

Check the references section for vendor advisories and patches from amazon. Update bedrock_agentcore_starter_toolkit to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
amazon bedrock_agentcore_starter_toolkit >= 0, < 0.1.13 Affected

Frequently Asked Questions

What is CVE-2026-4269?

CVE-2026-4269 is a high-severity vulnerability affecting amazon bedrock_agentcore_starter_toolkit. It was published on March 16, 2026 and has a CVSS 3.1 base score of 7.5 (HIGH).

How severe is CVE-2026-4269?

This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-4269?

Check the references section for vendor advisories and patches from amazon. Update bedrock_agentcore_starter_toolkit to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-4269?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-4269 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.

Browse by year 2026