
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection http://dlvr.it/TTtfyp #patchmanagement
Post summary
The post announces CVE-2026‑18655, which discloses broker credentials and OAuth tokens in AWS Labs Amazon MQ MCP Server through prompt injection, with no mention of patches, exploitation, or a PoC.
