CVE-2026-18655: Amazon MQ MCP Server prompt injection vulnerability
A prompt injection vulnerability in Amazon MQ MCP Server before version 2.0.24 allows remote unauthenticated actors to obtain RabbitMQ broker credentials or OAuth access tokens through improper endpoint restriction.
Disclosed 3 August 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated actors can obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens via crafted endpoints.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18655
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18954
