A AegiFlow
HIGHCVSS 7.3EPSS 0.1%

CVE-2026-16584

CVE-2026-16584 updated by NVD

Published
2026-07-24
Modified
2026-07-25
EPSS percentile
3%
Sources
github-advisory, nvd

Summary

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users should upgrade to version 1.3.47.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIawslabs.aws-api-mcp-server1.3.47

Remediation: Upgrade to 1.3.47 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.