A newly disclosed attack chain in Amazon Bedrock AgentCore that could turn a single malicious prompt into credential theft and compromise of other AI agents within the same AWS account and region.
Dubbed AgentCorruption, the research linked metadata access to an overprivileged execution role, enabling lateral movement, conversation exposure, memory poisoning, and theft of credentials for connected services.
AgentCore runs containerized agents inside Firecracker microVMs. Researchers demonstrated that an exposed agent equipped with HTTP or shell tools could be instructed to contact the local metadata endpoint at 169.254.169.254.
AWS Bedrock AgentCore Flaw
The resulting requests originated inside the workload, creating a server-side request forgery path to sensitive metadata. The endpoint returned temporary credentials for the agent’s execution role, including an access key ID, secret access key, and session token.
Researchers exported those credentials to their own machine and verified the assumed identity through AWS Security Token Service. Subsequent exploitation used AWS APIs directly, without further interaction with the compromised agent.
AWS documentation identifies this mechanism as the MicroVM Metadata Service, or MMDS, and warns that any code or actor inside the VM can retrieve execution-role credentials. The security consequence therefore depended heavily on permissions attached to that role.
According to Zenity, the default execution role included permissions extending beyond the compromised agent. Attackers could use logs:DescribeLogGroups to discover agent identifiers, then invoke other runtimes using bedrock-agentcore:InvokeAgentRuntime.
Broad Amazon Elastic Container Registry permissions also allowed retrieval of other agents’ container images, exposing application code and potentially embedded secrets. Memory permissions widened the impact further.
Researchers enumerated memory resources, actors, and sessions, then used bedrock-agentcore:ListEvents to retrieve stored conversations. Write and delete permissions enabled session tampering, allowing attacker-controlled content to influence an agent’s subsequent decisions.

The supplied overview additionally describes persistent manipulation through poisoned long-term memories and credential retrieval using bedrock-agentcore:GetResourceApiKey and secretsmanager:GetSecretValue.
These capabilities threatened authentication material intended for connected tools rather than direct exposure to agents. Zenity’s disclosure timeline states that AWS introduced IMDSv2-only behavior for newly deployed agents from February 14, 2026.
The researchers later observed substantial execution-role restrictions on September 29, including removing permissions that enabled broad agent invocation, conversation access, and Secrets Manager retrieval.
AWS characterized execution-role metadata access as documented and expected, emphasizing that cross-account access requires explicit authorization. Its guidance recommends least privilege and execution roles with no greater privileges than invoking users.
AgentCorruption illustrates how prompt-driven tool execution can inherit cloud authority, making tightly scoped IAM permissions essential to containing an agent compromise before it spreads to other workloads and sensitive resources.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

