CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

Published 2026-08-20T21:35:57Zd945f95094c06c32d001c81e4f4db0ed38ca13775c2089281f4072a228ce3353

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
173665fc119170f35cce4ee4553aedfca9cf2ea4
Public record ID
record:sha256:d945f95094c06c32d001c81e4f4db0ed38ca13775c2089281f4072a228ce3353

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
d945f95094c06c32d001c81e4f4db0ed38ca13775c2089281f4072a228ce3353
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection · Baitaphish