Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt...
UnratedCVE-2026-18655 · Published Aug 3, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions: Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument...
Affected versions
Details and references
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions: Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument before it executes, and can reject calls with hostnames that do not match the expected Amazon MQ endpoint pattern (e.g., .mq. .on.aws). References: CVE-2026-18655 GHSA-xwj6-8x5h-hjp6 Acknowledgement: We would like to thank Marios Gyftos for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-070-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655 , an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. Impacted versions: Resolution: This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24 . We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials. Workarounds: In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument before it executes, and can reject calls with hostnames that do not match the expected Amazon MQ endpoint pattern (e.g., .mq. .on.aws). References: CVE-2026-18655 GHSA-xwj6-8x5h-hjp6 A
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB... | Unrated | No fix yet |
| Aug 5 | Improper limitation of a pathname in AWS Transform MCP Server | Unrated | No fix yet |
| Aug 4 | AWS: code execution | Unrated | No fix yet |
| Aug 4 | Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation | Unrated | No fix yet |
| Aug 3 | Disabled SSH host key verification in AWS CLI EMR helper commands | Unrated | No fix yet |
| Jul 31 | Incorrect authorization in Strands Agents Tools http_request tool | Unrated | No fix yet |