HomeCVE Intelligence › CVE-2026-16584
CVSS 7.0 HIGH Vulnerability

CVE-2026-16584: AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to ma…

7.0CVSS Score
HIGHSeverity
NOCISA KEV
0.1%EPSS Score
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-16584
Vendorpip
Affected Productawslabs.aws-api-mcp-server
Vulnerability TypeVulnerability
CVSS Score7.0 (HIGH)
EPSS Score0.1% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Summary

The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. An issue exists where, if the data used to enforce this policy fails to initialize at server startup, the per-request policy check is silently skipped for the lifetime of the process.

Impact

On startup, the server loads data used to enforce the configured security policy. If that load fails, the server continues running without the enforcement data in place. In the default configuration, the pe

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-16584 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence