AgentCorruption: one prompt reached every AWS AgentCore agent
Zenity's AgentCorruption research shows one prompt to a public AWS AgentCore agent exposed every agent in the account. Here is how to scope your agent roles.
Zenity Labs published AgentCorruption on October 8: a chain of issues in Amazon Bedrock AgentCore where one prompt to one public-facing agent gave researchers control of every AgentCore agent in the same AWS account and region. No exploit kit. A chat message. If you run AI agents on AgentCore, or on any cloud runtime, the lesson is about the role your agent runs as, not the model.
What actually happened
Per Zenity's disclosure, presented at SecTor 2026 in Toronto, the researchers asked an internet-facing agent with a standard web-request tool to query the AWS Instance Metadata Service (IMDS). The agent's runtime let it reach IMDS and hand back temporary credentials for its execution role.
That default role was the problem. Its permissions covered all AgentCore agents in the account and region, not only the one agent. With it, Zenity says it could list and invoke internal agents, download container images and source code, read private conversations and long-term memories, and pull API keys and OAuth tokens from AWS Secrets Manager. It also planted malicious memories that sent future conversations to an attacker-controlled destination. Zenity's example: a customer service bot used as a door into an internal finance agent.
Zenity reported the issue to AWS on December 25, 2025. The Next Web reports that newly deployed agents have launched with IMDSv2 only since February 14, and that by September 29 AWS had removed the default role's ability to invoke other agents, read conversations and reach Secrets Manager. AWS disputes the framing. It told TNW the research "inaccurately paints expected and documented behavior as a vulnerability," and says customers should grant execution roles only the permissions each agent needs. There is no CVE.
Why AgentCore agent roles matter for your business
Your agent is as dangerous as its role. Prompt injection will get through eventually. What decides the damage is what the credentials behind the agent can touch. A public chatbot should not hold a key that opens your finance agent.
Defaults changed for new agents, not your old ones. The IMDSv2 change applies to newly deployed agents. If you shipped an AgentCore agent before mid-February, or copied an old role template, check it yourself.
Split public and internal agents. Separate execution roles at minimum. Separate AWS accounts if the internal agent touches money or customer records. Treat memory as an attack surface and review what gets written to it.
Key takeaways
- One prompt to a public AgentCore agent exposed every agent in the same account and region, per Zenity
- The path: agent web tool → instance metadata → over-broad default execution role
- AWS made IMDSv2 the default for new agents and narrowed the default role; it calls the rest documented behavior
- Audit every existing agent's execution role and scope it to that one agent
- Keep customer-facing and internal agents in separate roles or accounts
Running agents in the cloud on a default role? We build AI agents with one scoped role per agent, logged tool calls, and no shared keys between the bot your customers talk to and the systems that move money. See how we build agents or ask us to review your setup.
Sources: Zenity Labs, The Next Web.
- #aws-agentcore
- #ai-agents
- #agent-security
- #iam
- #prompt-injection
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Vesta raises $30M: mortgage AI agents earn autonomy in steps
Vesta's $30M round funds AI agents for mortgage origination, with customers investing too. The rollout model—human approval first—works for any small business.
Read itnCino + Parlay: AI SBA loan intake comes to 1,400 lenders
nCino will resell Parlay's AI SBA loan intake to banks. If you plan to borrow, an AI now screens your file first. Here's how to make it credit-ready.
Read it