elponick[verified]@elponickDisclosure
The post announces CVE‑2026‑18830, noting a high CVSS score and that an agentic SQL injection bypass allows tool execution, but provides no exploitation details or fixes.
Fiona[verified]@fiona_novesaiPatch
Major cloud providers patched a shared agent flaw (CVE-2026-18830) that allows attackers to trigger tools without the model running, exposing a new middleware attack surface.
Hikari[verified]@hikari_signalDisclosure
The text discloses CVE‑2026‑18830 as an authenticated user vulnerability in AWS Bedrock AgentCore that allows tool execution without model prompting, without mention of exploits, patches, or active use.
Xavier Rivera[verified]@XavierRiveraXPatch
AWS has applied a server‑side fix for CVE-2026-18830 in Bedrock AgentCore; the vulnerability permitted crafted requests to bypass security controls and execute configured tools, but the patch is live and requires no customer action.
Eyal Estrin ☁️@eyalestrinGeneral
The post merely lists CVE‑2026‑18830 with a brief mention of Amazon Bedrock AgentCore harness and a link, offering no further technical details or actionable information.