---
id: CVE-2026-87913
title: >-
  A missing S3 bucket ownership verification in the AWS Security Agent MCP
  server before 0.2.0 version might allow remote attackers to obtain the private
  source archive of a scanned workspace, including credentials and
  infrastructure state…
summary: >-
  A missing S3 bucket ownership verification in the AWS Security Agent MCP
  server before 0.2.0 version might allow remote attackers to obtain the private
  source archive of a scanned workspace, including credentials and
  infrastructure state…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'
cwe:
  - CWE-283
  - CWE-341
vendor: AWS
product: AWS Security Agent MCP server
affected:
  - security_agent_mcp_server >= 0.1.0 <= 0.1.5
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:54:25.810'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87913'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-105-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/awslabs/mcp/security/advisories/GHSA-3jxw-vj8m-8x77'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://pypi.org/project/awslabs.security-agent-mcp-server/0.2.0/?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T16:27:54.762829Z'
ingestedAt: '2026-09-14T08:22:42.788Z'
epss: 0.00441
epssPercentile: 0.35647
---

## Overview

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.



To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
