Junglewise Threat Intelligence

CVE-2026-18655: AWS Amazon MQ MCP Server credential disclosure via prompt injection

CVE-2026-18655 · Severity: high · CVSS 7.5 · Published 2026-09-22

Executive brief

AWS Amazon MQ is a managed message broker service used for application communication in cloud environments. A prompt injection vulnerability in the Amazon MQ MCP Server allows attackers to trick the server into disclosing sensitive credentials and authentication tokens through specially crafted inputs. This could enable unauthorized access to message brokers, compromise data in transit, and provide a foothold for further cloud infrastructure attacks.

Technical details

CVE-2026-18655 is a prompt injection vulnerability in the AWS Labs Amazon MQ Model Context Protocol (MCP) server implementation. The vulnerability stems from insufficient input validation or sanitization of user prompts, allowing attackers to inject malicious commands that cause the server to leak broker credentials and OAuth tokens. The attack is network-reachable and requires the attacker to interact with the MCP server interface; no pre-authentication is specified as a requirement. A successful exploit grants an attacker access to sensitive authentication material that could be used to compromise Amazon MQ brokers and potentially pivot to other AWS resources. Patches or mitigations should be available through AWS security updates.

Affected products

  • AWS Amazon MQ MCP Server <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats