Editorial illustration for AWS AgentCore's default permissions bypass its own credential security advice
AWS AgentCore Bypasses Own Security Credentials
AWS AgentCore's default permissions bypass its own credential security advice
Amazon built Bedrock AgentCore to run enterprise AI agents with memory, tools, and access controls baked in. The sales pitch is isolation: every agent gets its own lane, its own credentials, its own blast radius if something goes wrong. Researchers at Zenity Labs decided to test that promise by sending one chat message to one public-facing agent.
That single message was enough to reach into every other AgentCore agent running in the same AWS account and region, according to Zenity's findings. The firm's team traced a chain of flaws they're calling "AgentCorruption," rooted in how AgentCore handed out default permissions across an entire region rather than locking each agent down individually. An attacker with nothing more than normal chat access to one agent could, in theory, pivot straight into internal AWS credentials belonging to unrelated agents.
AWS designed AgentCore with security guidance that tells customers to scope credentials tightly and keep agents isolated from one another. Zenity's work suggests the platform's own defaults didn't follow that advice, leaving a gap between what AWS recommends and what it ships by default.
An attacker needed only chat access to one public agent to exploit the flaws. The researchers say a single prompt let them take over every AgentCore agent in the same AWS account and region, exposing private conversations, source code, and stored credentials.
Why this matters
This isn't a bug in one agent. It's a design flaw in the scaffolding meant to keep agents apart. AWS tells customers to isolate credentials in secure storage, then ships a platform where default region-wide permissions let any compromised agent reach into that storage anyway.
Zenity's researchers needed exactly one prompt to a single public-facing agent to pivot across an entire account's fleet. For teams building on AgentCore, that's a blunt lesson: read the default permission model before you trust the vendor's own security guidance, because the two can contradict each other.
The bigger worry is scale. Multi-agent deployments are becoming the default architecture for anything beyond a demo, and each new agent is another credentialed identity with network access. If the platform underneath doesn't enforce isolation by default, every agent you add is another door, not another feature. Before shipping agents into production, founders and engineering leads should be auditing IAM scopes and credential boundaries themselves, not assuming the managed service already did it.
Common Questions Answered
How did Zenity Labs researchers exploit AWS AgentCore's security isolation?
Zenity Labs researchers discovered that a single chat message sent to one public-facing AgentCore agent was sufficient to bypass isolation controls and gain access to every other AgentCore agent running in the same AWS account and region. This single prompt allowed attackers to expose private conversations, source code, and stored credentials across the entire agent fleet, demonstrating that the default region-wide permissions override AWS's own credential security recommendations.
What is the core design flaw in AWS AgentCore's default permissions?
AWS AgentCore's default permissions are configured at the region level, which allows any compromised agent to reach into secure credential storage meant for other agents in the same account and region. This contradicts AWS's own guidance to isolate credentials in secure storage, as the platform's default settings grant overly broad permissions that enable lateral movement between supposedly isolated agents.
What was AWS AgentCore originally designed to provide according to the article?
AWS AgentCore was built to run enterprise AI agents with memory, tools, and access controls integrated into the platform, with the primary selling point being isolation—ensuring each agent operates in its own isolated lane with its own credentials and blast radius. However, Zenity's research revealed this isolation promise was not delivered due to the default permission configuration.
What information could attackers access after exploiting the AgentCore vulnerability?
After exploiting the AgentCore vulnerability through a single prompt to a public-facing agent, attackers could access private conversations between users and other agents, source code used by those agents, and stored credentials. This exposed sensitive data across every AgentCore agent running in the compromised AWS account and region.
Further Reading
- Security best practices for AgentCore Runtime - AWS Documentation
- IAM permissions - AWS AgentCore CLI GitHub
- Security and access controls - Amazon Bedrock AgentCore - AWS Documentation
- Security and IAM roles - Amazon Bedrock - AWS Documentation
- Securing AI agents with Amazon Bedrock AgentCore Identity - AWS Security Blog