Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-18655: Amazon MQ MCP Server prompt injection vulnerability

A prompt injection vulnerability in Amazon MQ MCP Server before version 2.0.24 allows remote unauthenticated actors to obtain RabbitMQ broker credentials or OAuth access tokens through improper endpoint restriction.

Disclosed 3 August 2026 · Record updated 13 September 2026

Impact

Remote unauthenticated actors can obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens via crafted endpoints.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18655
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18954