CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server

Published 2026-09-09T21:30:11Zc809cd46f48ccf4aaba686981f32f10d5b1d06a86862614db70922469f2d850e

Source metadata

Publication date
2026-09-09T21:30:11Z
Source identifier
a41ef7e97f89d1c93a812d41151217ad1b95348b
Public record ID
record:sha256:c809cd46f48ccf4aaba686981f32f10d5b1d06a86862614db70922469f2d850e

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
c809cd46f48ccf4aaba686981f32f10d5b1d06a86862614db70922469f2d850e
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server · Baitaphish