Skip to content
Brief Security & Trust ·

Zenity says one prompt exposed every AgentCore agent in an AWS account and region

Zenity Labs says one exposed agent with any tool that can send outbound traffic gave access to every agent in its AWS account and region.

In brief
  • Zenity Labs says one exposed AgentCore agent with any tool that can send outbound traffic gave its researchers access to all agents in the same AWS account and region.
  • AWS says new agents have used IMDSv2 since February 14, 2026. The sources do not say whether older agents are still exposed.

Zenity Labs, a security firm, says its researchers took over every AI agent in one AWS account and region, starting from one exposed Amazon Bedrock AgentCore agent. Zenity says the agent needed any tool that can send outbound traffic, such as an HTTP or shell tool. Its test agent, built with AWS's Strands toolkit, was asked to fetch an internal metadata address. This trick is called server-side request forgery (SSRF). Zenity says the agent returned temporary cloud credentials that also worked from the researchers' own machine. Zenity says removing the web tool would not have helped, as the flaw is in the platform.

Zenity says the role's default permissions reached all agents in the account and region, so the researchers could pull other agents' code images. Zenity says AWS closed the report as "informative" on April 12, 2026, and that new agents have used the stricter IMDSv2 since February 14, 2026. The sources do not say whether older agents remain exposed or whether the default permissions changed. The Decoder noted that Zenity sells AI agent security tools.

WebPulse analysis, not a Zenity claim: if one role spans a whole region, a per-agent sandbox protects little, because one weak agent opens the rest. Teams running agents could ask: Which role does each agent run under? Do any roles use wildcard registry or log permissions?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Zenity Labs.