CVE-2026-5058Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the MCP server. Was ZDI-CAN-27968.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • False Positive: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-13); latest day: 1
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-11: 2Mentions · 2026-04-13: 3Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-02: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-11: 2Technical Details · 2026-04-13: 3Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-0204-0304-1104-1304-1904-21
Signal classification3 categories
Disclosure
444.4%
Patch
444.4%
False Positive
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-031
False Positive1
2026-04-112
Disclosure1Patch1
2026-04-133
Disclosure1Patch2
2026-04-191
Disclosure1
2026-04-211
Patch1
Full discourse9 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-246|CVE-2026-5058] (0Day) aws-mcp-server Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Alfredo Oliveira and David Fiser of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-246/

    Post summary

    The zero‑day advisory announces CVE-2026-5058, a command injection RCE flaw in aws-mcp-server with a CVSS of 9.8, and directs readers to a link for further details.

    010323.3K
    5.5K followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    Patch

    AWS-MCP-Server (CVE-2026-5058) command injection is a critical reminder. MCP servers are privileged execution environments. Static scans miss runtime context. Production agents need execution-time authorization to block RCE. 🛡️ #MCPSecurity #AISecurity #MCP

    Post summary

    The post highlights a command‑injection flaw in AWS‑MCP‑Server (CVE‑2026‑5058) and stresses that static scans miss runtime context, advising the use of execution‑time authorization to mitigate RCE risk.

    2001051
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5058: aws-mcp-server Command Injection ... Unauthenticated RCE in AWS MCP server via command injection - CVSS 9.8 means instant shells for anyone who finds this in... https://zerodaysignal.com/vulnerability/CVE-2026-5058 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a critical command injection vulnerability in AWS MCP Server (CVSS 9.8), highlighting unauthenticated remote code execution without providing PoC or exploit code.

    0002099
    217 followersView on X
  • Kwaza ICT@KwazaIct
    Patch

    CVE-2026-5058: Critical command injection in aws-mcp-server. Remote code execution possible. Patch immediately and review security protocols to safeguard your systems. #AWS #CyberSecurity

    Post summary

    The post alerts to a critical command injection flaw in aws-mcp-server and urges immediate application of an available patch.

    0002064
  • Autumn Good@autumn_good_35
    False Positive

    『The vendor rejected the vulnerability』 CVE-2026-5058 (0Day) aws-mcp-server Command Injection Remote Code Execution Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-26-246/ CVE-2026-5059 (0Day) aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-26-245/

    Post summary

    The vendor has denied the validity of the reported vulnerabilities, with no proof‑of‑concept, exploit, or patch details provided in the text.

    01010381
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … https://www.cve.org/CVERecord?id=CVE-2026-5058

    Post summary

    CVE‑2026‑5058 describes a command‑injection flaw in aws‑mcp‑server that allows attackers to run arbitrary code on affected installations. The brief note provides a direct link to the CVE record but no proof of exploitation or mitigation steps.

    00001199
    57.2K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-5058 - aws-mcp-server RCE (CVSS 9.8) Unauthenticated command injection allows remote code execution. Flaw in allowed commands list validation enables attackers to execute arbitrary code. Patch immediately. #CVE #PatchNow https://t.co/23tyctdpZR

    Post summary

    CVE-2026-5058 is a critical RCE vulnerability in aws-mcp-server that allows unauthenticated command injection; the tweet urges immediate patching.

    0000061
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5058 Unauthenticated Command Injection Remote Code Execution in aws-mcp-server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5058

    Post summary

    A brief disclosure of CVE-2026-5058 noting an unauthenticated command injection vulnerability that can lead to remote code execution in aws-mcp-server is presented, with no PoC, exploit, or patch information.

    0000077
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5058: CRITICAL] Critical remote code execution vulnerability (ZDI-CAN-27968) in aws-mcp-server allows attackers to run arbitrary code without authentication. Ensure immediate patching to stay secure.#cve,CVE-2026-5058,#cybersecurity https://cvefind.com/CVE-2026-5058

    Post summary

    The tweet announces a critical remote code execution vulnerability in aws-mcp-server and urges users to apply patches immediately.

    0000095
    619 followersView on X

Explore more