AWS API MCP Server Security Policy Bypass via Startup Failure
UnratedCVE-2026-16584 · Published Jul 23, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 08:30 AM PDT Description: The AWS API MCP Server (awslabs.aws-api-mcp-server) is an open-source MCP server that lets AI assistants execute AWS CLI commands against a user's AWS account. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. We identified CVE-2026-16584 . On startup, the server loads the data used to enforce this security policy. If that initialization fails, the server continues running with the per-request policy check skipped for the lifetime of the process. When a security policy is configured without the fail-closed modes enabled, an actor could then cause AWS API operations that the policy was configured to deny or gate to execute without enforcement. IAM permissions on the configured credentials remain in effect and are unaffected. Impacted versions: >= 0.2.13 AND Resolution: This issue has been addressed in awslabs.aws-api-mcp-server version 1.3.47 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until...
Affected versions
Details and references
Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 08:30 AM PDT Description: The AWS API MCP Server (awslabs.aws-api-mcp-server) is an open-source MCP server that lets AI assistants execute AWS CLI commands against a user's AWS account. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. We identified CVE-2026-16584 . On startup, the server loads the data used to enforce this security policy. If that initialization fails, the server continues running with the per-request policy check skipped for the lifetime of the process. When a security policy is configured without the fail-closed modes enabled, an actor could then cause AWS API operations that the policy was configured to deny or gate to execute without enforcement. IAM permissions on the configured credentials remain in effect and are unaffected. Impacted versions: >= 0.2.13 AND Resolution: This issue has been addressed in awslabs.aws-api-mcp-server version 1.3.47 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Until you can upgrade, any one of the following prevents the bypass: Use least-privilege IAM credentials (for example, a ReadOnlyAccess role) scoped to the task. IAM remains the primary access control and is enforced regardless of this issue. If the server started while connectivity was degraded, restart it once connectivity is restored so the policy enforcement data loads successfully. References: CVE-2026-16584 GHSA-29w2-fq35-v728 Acknowledgement: We would like to thank Lav Kumar Vishwakarma (independent security researcher) on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-063-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 08:30 AM PDT Description: The AWS API MCP Server (awslabs.aws-api-mcp-server) is an open-source MCP server that lets AI assistants execute AWS CLI commands against a user's AWS account. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. We identified CVE-2026-16584 . On startup, the server loads the data used to enforce this security policy. If that initialization fails, the server continues running with the per-request policy check skipped for the lifetime of the process. When a security policy is configured without the fail-closed modes enabled, an actor could then cause AWS API operations that the policy was configured to deny or gate to execute without enforcement. IAM permissions on the configured credentials remain in effect and are unaffected. Impacted versions: >= 0.2.13 AND Resolution: This issue has been addressed in awslabs.aws-api-mcp-server version 1.3.47 . We recommend upgrading to the latest version and ensuring any forked or derivative code is
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK... | Unrated | No fix yet |
| Jul 23 | Allocation of resources without limits in the default aws-smithy-http-server serve() path... | Unrated | No fix yet |
| Jul 22 | AWS CDK CodeBuild S3 Log Encryption Boolean Inversion | Low3.3 | 2.253.0+2 more |
| Jul 21 | QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls | Medium5.3 | 1.7.6 |
| Jul 21 | Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols | Unrated | No fix yet |
| Jul 21 | Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows... | Unrated | No fix yet |