CVE-2026-11393
Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS account, via a crafted collaborationInstruction stored on a Bedrock Agent collaborator and later processed by that other user during agent import.
To remediate this issue, users should upgrade to version 0.14.2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1098Account Manipulationpersistence · privilege escalation70 %
Requiere autenticación (PR:L) e interacción del usuario (UI:A) para importar agente. La inyección de código Python en instrucciones colaborativas se ejecuta cuando otro usuario procesa el artefacto, encajando en explotación para ejecución en cliente (T1203). El impacto es ejecución arbitraria de cód
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-94
Referencias
- https://aws.amazon.com/security/security-bulletins/2026-040-aws/
- https://github.com/aws/agentcore-cli/releases/tag/v0.14.2
- https://github.com/aws/agentcore-cli/security/advisories/GHSA-m4x6-gwgp-4pm7
- https://www.npmjs.com/package/@aws/agentcore/v/0.14.2
- https://www.npmjs.com/package/@aws/agentcore/v/1.0.0-preview.9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-11393",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-11393",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-08T19:45:52.025563Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.8,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "ACTIVE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"affectedData": [
{
"vendor": "AWS",
"product": "AgentCore CLI",
"versions": [
{
"status": "affected",
"version": "0.4.0",
"versionType": "custom",
"lessThanOrEqual": "0.14.1"
},
{
"status": "affected",
"version": "0.3.0-preview.7.0",
"versionType": "custom",
"lessThanOrEqual": "1.0.0-preview.8"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-08T19:16:41.270",
"references": [
{
"url": "https://aws.amazon.com/security/security-bulletins/2026-040-aws/",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://github.com/aws/agentcore-cli/releases/tag/v0.14.2",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://github.com/aws/agentcore-cli/security/advisories/GHSA-m4x6-gwgp-4pm7",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://www.npmjs.com/package/@aws/agentcore/v/0.14.2",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://www.npmjs.com/package/@aws/agentcore/v/1.0.0-preview.9",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS account, via a crafted collaborationInstruction stored on a Bedrock Agent collaborator and later processed by that other user during agent import.\n\n\n\nTo remediate this issue, users should upgrade to version 0.14.2."
},
{
"lang": "es",
"value": "La neutralización incorrecta de caracteres de triple comilla durante la generación de código Python en AgentCore CLI antes de la v0.14.2 podría permitir que un actor de amenaza remoto autenticado ejecute código arbitrario en el tiempo de ejecución de AWS AgentCore bajo el rol de ejecución de IAM del agente importado y en el entorno local de otro usuario en la misma cuenta de AWS, a través de una collaborationInstruction especialmente diseñada almacenada en un colaborador de Bedrock Agent y procesada posteriormente por ese otro usuario durante la importación del agente.\n\nPara remediar este problema, los usuarios deberían actualizar a la versión 0.14.2."
}
],
"lastModified": "2026-07-23T08:10:00.137",
"sourceIdentifier": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
}