
Security researchers at Zenity Labs have disclosed a chain of flaws in Amazon Bedrock AgentCore that historically allowed a public-facing AI agent to reach sensitive runtime metadata and use stolen AWS credentials to access other agents in the same AWS account and Region.
The researchers described the chain as AgentCorruption. In their testing, a single prompt sent to an exposed AgentCore agent was enough to trigger access to the runtime metadata service, obtain temporary AWS credentials and move beyond the original agent’s security boundary. The resulting access could expose other agents’ container images, conversations, memory and credentials, depending on the permissions attached to the compromised execution role.
Zenity reported the initial metadata finding to AWS on December 25, 2025 and later reported the wider cross-agent impact. AWS changed parts of AgentCore before the research was publicly disclosed on October 8, 2026, including moving newly deployed runtimes to a stricter metadata-access mechanism and reducing permissions in the default execution role.
The initial foothold involved the runtime metadata service at 169.254.169.254. Zenity used an AgentCore agent built with AWS’s Strands SDK and a tool capable of making network requests. A prompt caused the agent to request the metadata endpoint, which exposed information about the runtime and the IAM role associated with it.
The researchers obtained temporary AWS STS credentials for that role and confirmed that AWS accepted them as the identity of the running agent. That changed the attack from manipulating an AI agent through a prompt to making authenticated AWS API requests outside the original agent session.
Zenity also reported finding additional runtime information through the metadata interface, including the AWS account ID, runtime details, an ECR image reference and instance tags. The researchers said the metadata included a presigned S3 URL and that environment variables exposed through the metadata user-data endpoint could contain secrets such as an OPENAI_API_KEY.
The larger problem was the permissions available to the stolen identity. Zenity found that the historical default AgentCore execution role was not restricted to resources belonging to the individual agent.
CloudWatch permissions could be used to enumerate log groups associated with AgentCore runtimes. The naming information in those log groups helped the researchers identify other agents deployed in the same account and Region.
From there, ECR permissions could be used to retrieve container images associated with other agents. Zenity said the images could then be inspected for source code, configuration, endpoints and other sensitive information.
The role also allowed bedrock-agentcore:InvokeAgentRuntime with broad scope. That gave the researchers a way to invoke other AgentCore agents rather than remaining confined to the original public-facing workload.
In one demonstration, the researchers identified another agent, examined its available capabilities and used its file operation functionality to retrieve a sensitive billing.json file. The result depended on what the target agent and its tools were authorized to access, but it showed how a compromised agent could become a route to a second workload.
The cross-agent access extended into AgentCore Memory. Zenity found that the compromised role could enumerate memory IDs, actors, sessions and session events, allowing the researchers to retrieve conversation data associated with other agents.
The researchers also found permissions that allowed events to be created and deleted. In a demonstration, they inserted fabricated conversation content into an existing session, including instructions directing a customer-support agent to send a refund to an attacker-controlled bank account. The test showed the ability to manipulate the context used by an agent; whether such a manipulated instruction would result in a real transaction would still depend on the target agent’s tools and authorization.
More concerningly, Zenity demonstrated that manipulated short-term events could be processed by AgentCore’s long-term memory strategies. The researchers used this behavior to create persistent malicious context that could survive beyond the original interaction.
One demonstration used poisoned memory to instruct an agent to contact an attacker-controlled webpage before answering future users. Zenity used the external page as a command-and-control mechanism, allowing the behavior to be changed later without modifying the agent’s memory again. The researchers also demonstrated using the channel to forward subsequent conversations to an external collection endpoint.
The research identified another path through credentials stored for AgentCore integrations. Zenity found that the historical execution role could access certain Secrets Manager entries and AgentCore Identity provider information. By combining that access with container-image inspection and provider enumeration, the researchers said they could identify API keys and OAuth credentials used to connect agents to external services.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



