VulnerabilitiesUnit 42 finds credential leak path in AWS AgentCore Harness
Palo Alto Networks researchers say default settings leave a gap between the agent runtime and identity management that prompt injection can exploit.
18 Sept 2026
Security researchers at Unit 42 found that default configurations in AWS AgentCore Harness create a gap between the agent runtime and identity management, allowing prompt injection attacks to exfiltrate credentials from agents.
Disclosed 18 September 2026 · Record updated 18 September 2026
Default configurations in AWS AgentCore Harness can allow attackers to use prompt injection to exfiltrate credentials from agents, exposing an identity/credential management gap.
VulnerabilitiesPalo Alto Networks researchers say default settings leave a gap between the agent runtime and identity management that prompt injection can exploit.
18 Sept 2026