Back to overview

CVE-2026-16584

HIGH
7.0
CVSS 3.1
Description
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users should upgrade to version 1.3.47.

Metadata

CVE ID
CVE-2026-16584
State
PUBLISHED
Assigner
AMZN
Reserved
2026-07-22 13:43 UTC
Published
2026-07-23 15:34 UTC
Last updated
2026-07-23 18:16 UTC
Primary CWE
CWE-455
CWE-455 Non-exit on failed initialization
Vendor / Product
AWS / aws-api-mcp-server
Sources
cve.org  ·  NVD

Severity & Metrics

7.0 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
AWS aws-api-mcp-server 0.2.13 < 1.3.47
Weakness (CWE)
CWESourceDescription
CWE-455 cna CWE-455 Non-exit on failed initialization
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.3 HIGH 4.0 cna CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.0 HIGH 3.1 cna CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview