AWS AgentCore Harness Bypass Exposed a Cross-Platform Vulnerability Class in Agent Runtimes
The AgentCore Harness Bypass: A Structural Vulnerability A critical vulnerability in the AWS Bedrock AgentCore harness, identified as CVE-2026-18830, has exposed a fundamental flaw in how agentic systems process tool execution requests. With a CVSS score of 8.6, this vulnerability allowed authenticated users to execute tools while bypassing essential model invocation and security controls. The…