Zenity reports a scoped takeover path in AWS AgentCore
Zenity Labs disclosed research describing how a prompt to one public-facing AWS AgentCore agent could expose other agents in the same AWS account and region. AWS disputed Zenity’s characterization of the behavior as a vulnerability, and Zenity said AWS’s security team patched the findings.

Key takeaways · 3
- 01
The demonstrated path began with a prompt to one public-facing agent that had a tool for outbound requests.
- 02
Zenity said the credentials exposed a default role with permissions covering AgentCore agents in the same account and region—not every agent in the region.
- 03
Zenity said AWS removed permissions for wide agent execution, private-conversation access and Secrets Manager access across an account’s region.
How the prompt led to access
Zenity presented its AgentCorruption research at the SecTor 2026 conference in Toronto and disclosed it on October 8, 2026.[1] The demonstration began with a prompt to a public-facing AgentCore agent equipped with a tool that could make outbound requests.[1] Zenity said the prompt directed the agent to contact the Instance Metadata Service, which can provide temporary credentials to cloud workloads.[1] According to Zenity, AgentCore’s infrastructure let the agent reach that endpoint and retrieve credentials assigned to its underlying machine.[1] The chain depended on the agent’s ability to make the request and the permissions attached to the retrieved credentials.[1]
What the credentials exposed
Zenity said the credentials belonged to a default IAM role whose permissions extended to AgentCore agents within the same AWS account and region.[1] Researchers could use that role to discover and invoke agents they were not authorized to access, download agent container images, and retrieve source code.[1] Zenity also said they could read private conversations and long-term memories across agents, users and sessions, as well as access API keys, OAuth tokens and other credentials stored in AWS Secrets Manager and environment variables.[1] Zenity further reported that agent memory could be used to plant instructions affecting behavior and directing future conversations to an attacker-controlled destination.[1]
Scope and competing accounts
The research did not demonstrate control over every AgentCore agent across an AWS region: Zenity said the takeover was confined to agents in the same account and region.[1] AWS said Zenity inaccurately characterized expected and documented AgentCore behavior as a vulnerability.[2] AWS also said access to another AWS account’s resources requires a developer to explicitly grant permissions on both the agent’s execution role and the target resource.[2] Separately, Zenity said AWS told it that newly deployed AgentCore agents had used IMDSv2 only since February 14.[2] The published evidence does not identify a CVE; The Next Web said Zenity’s disclosure included no CVE identifier.[2]
Reports and remediation
Zenity said it reported metadata-service access to AWS on December 25, 2025, and the broad default role on January 12, 2026.[3] It said AWS closed its initial metadata-access report as “informative” on April 12, 2026, and that it confirmed on June 22, 2026, that the default execution-role permissions remained unchanged.[3] Zenity later said AWS removed permissions that had enabled wide agent execution, access to private conversations and access to Secrets Manager secrets across an account’s region.[3] Zenity said AWS’s security team had patched the findings.[3] AWS recommends limiting execution roles to the permissions agents need.[2]
For teams deploying AI agents, this case makes the boundary between an agent’s tools and its cloud execution permissions a practical security decision. Review outbound-request capabilities and role permissions together, while distinguishing the reported same-account-and-region scope from cross-account access.
Why it matters
Put this to work — one session a day, built for your industry.
Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.
Start freeHow this developed
11 October 2026
Zenity reports a scoped takeover path in AWS AgentCore