Unit 42 Discovers 'Agent God Mode' Vulnerability in Amazon Bedrock AgentCore
Palo Alto Networks' Unit 42 has identified a critical security vulnerability termed 'Agent God Mode' within Amazon Bedrock AgentCore. The issue stems from the default configuration of the AgentCore starter toolkit, which automatically generates Identity and Access Management (IAM) roles with overly broad permissions. Instead of adhering to the principle of least privilege, these default roles grant agents unrestricted access across the entire AWS account. This misconfiguration allows attackers who compromise a single agent to escalate privileges, exfiltrate proprietary Elastic Container Registry images, access other agents' memory stores, and invoke code interpreters arbitrarily. The vulnerability effectively enables an attacker to compromise every AgentCore agent within an affected account. Upon disclosure of these findings, AWS updated its documentation to warn that default roles are intended solely for development and testing, not production environments. This analysis highlights significant risks in cloud AI deployment tools where ease of setup compromises security boundaries, potentially leading to severe data breaches and privilege escalation attacks in enterprise cloud infrastructure.
Wire timeline
Unit 42 Discovers 'Agent God Mode' Vulnerability in Amazon Bedrock AgentCore
Palo Alto Networks' Unit 42 has identified a critical security vulnerability termed 'Agent God Mode' within Amazon Bedrock AgentCore. The issue stems from the default configuration of the AgentCore starter toolkit, which automatically generates Identity and Access Management (IAM) roles with overly broad permissions. Instead of adhering to the principle of least privilege, these default roles grant agents unrestricted access across the entire AWS account. This misconfiguration allows attackers who compromise a single agent to escalate privileges, exfiltrate proprietary Elastic Container Registry images, access other agents' memory stores, and invoke code interpreters arbitrarily. The vulnerability effectively enables an attacker to compromise every AgentCore agent within an affected account. Upon disclosure of these findings, AWS updated its documentation to warn that default roles are intended solely for development and testing, not production environments. This analysis highlights significant risks in cloud AI deployment tools where ease of setup compromises security boundaries, potentially leading to severe data breaches and privilege escalation attacks in enterprise cloud infrastructure.
Unit 42