CVE-2026-5059Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the MCP server. Was ZDI-CAN-27969.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • False Positive: 1 classified signal
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-04-03); latest day: 1
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-04-02: 1Mentions · 2026-04-03: 2Mentions · 2026-04-11: 2Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-11: 2Technical Details · 2026-04-13: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-19: 104-0204-0304-1104-1304-1504-19
Signal classification4 categories
Disclosure
562.5%
False Positive
112.5%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-032
Disclosure1False Positive1
2026-04-112
Disclosure1General1
2026-04-131
Patch1
2026-04-151
Disclosure1
2026-04-191
Disclosure1
Full discourse8 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-245|CVE-2026-5059] (0Day) aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Alfredo Oliveira and David Fiser of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-245/

    Post summary

    The advisory discloses a critical zero‑day AWS CLI command injection (CVE‑2026‑5059) with a CVSS score of 9.8, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    021525.1K
    5.5K followersView on X
  • Yutan@yutaaaalll
    Disclosure

    MCPサーバーのセキュリティが表面化してきた。CVE-2026-5059、非公式aws-mcp-serverのコマンドインジェクション(CVSS 9.8)。ZDIが0-dayとして公開したけど、対象は個人リポジトリでスター200未満。MCPエコシステムが広がるほど、こういう野良サーバーのリスクは増える #MCP #Security #AI

    Post summary

    A zero‑day command‑injection vulnerability (CVE‑2026‑5059) with a CVSS score of 9.8 has been disclosed by ZDI, targeting unofficial AWS MCP servers, highlighting significant risks for privately hosted repositories.

    30000270
    562 followersView on X
  • Autumn Good@autumn_good_35
    False Positive

    『The vendor rejected the vulnerability』 CVE-2026-5058 (0Day) aws-mcp-server Command Injection Remote Code Execution Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-26-246/ CVE-2026-5059 (0Day) aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-26-245/

    Post summary

    The text notes a vendor rejection of two 0Day command-injection CVEs, with no PoC, exploit, or patch details provided, implying a false-positive or debunked report.

    01010381
    6.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5059: CRITICAL] Critical AWS CLI Command Injection vulnerability (ZDI-CAN-27969) in aws-mcp-server allows remote code execution without authentication. Attackers can exploit unvalidated user input to...#cve,CVE-2026-5059,#cybersecurity https://cvefind.com/CVE-2026-5059

    Post summary

    The post announces a critical AWS CLI command injection flaw (CVE‑2026‑5059) that permits unauthenticated remote code execution.

    0001090
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5059 aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat… https://www.cve.org/CVERecord?id=CVE-2026-5059

    Post summary

    A new vulnerability (CVE-2026-5059) in AWS CLI allows remote attackers to execute arbitrary code via command injection.

    00000198
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical command injection vulnerability (CVE-2026-5059) affecting `aws-mcp` could lead to remote code execution. Assess your `aws-mcp` deployments for exposure and prepare for remediation. #aws #infosec #rce https://www.pulsepatch.io/posts/cve-2026-5059-aws-mcp-command-injection-rce

    Post summary

    A critical command injection flaw in aws‑mcp could allow remote code execution; stakeholders should assess exposure and plan remediation.

    0000029
    12 followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2026-5059: aws-mcp-server AWS CLI Command In... Unauthenticated RCE via command injection in AWS MCP server's allowed commands handler—CVSS 9.8 screams "patch immediate... https://zerodaysignal.com/vulnerability/CVE-2026-5059 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑5059 as an unauthenticated remote code execution flaw in AWS MCP server command injection with a CVSS 9.8 score, urging users to apply patches immediately.

    0000064
    217 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5059 Unauthenticated Command Injection Remote Code Execution in aws-mcp-server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5059

    Post summary

    The text references CVE-2026-5059, noting it as unauthenticated command injection that results in RCE on the aws-mcp-server, with a link to a detailed vulnerability page.

    0000057
    4.0K followersView on X

Explore more