Zenity Labs showed that a single plain-language prompt to a public-facing Amazon Bedrock AgentCore test agent could make it fetch its temporary AWS credentials from the instance metadata service and send them out. The default execution role then reached other agents in the same account and region. AWS has since made IMDSv2 the default and narrowed that role; AWS disputes calling the behavior a vulnerability.
THE CONTROL LESSON
What should we watch for?
Ackuity's view: treat a metadata-endpoint fetch plus an outbound POST of credentials as a sequence to block before it runs. Scope the execution role to what that one agent needs; do not rely on the prompt to keep the agent away from IMDS.
THE EVIDENCE
What does the report establish?
This was a research demonstration on Zenity's own test agent, not a reported customer breach. Zenity sells agent security. On October 9, 2026, AWS told The Decoder the research "inaccurately paints expected and documented behavior as a vulnerability," and that cross-account access requires explicit grants. Zenity stated the issue did not cross the account boundary and has been fully mitigated.
Read the full account
On October 8, 2026, Zenity Labs published "AgentCorruption: Initial IMDS Access," describing a researcher-built public-facing Amazon Bedrock AgentCore agent (Strands SDK with an HTTP tool). In plain language they asked it to GET the instance metadata service at 169.254.169.254 and POST the results to their listener. The agent returned temporary STS credentials for its execution role, which worked from the researchers' own machine outside AgentCore. Zenity says the default role then let them reach other AgentCore agents in the same AWS account and region (source code via ECR, private conversations, and further permissions they describe in follow-on posts). They reported findings to AWS in December 2025; Zenity says AgentCore moved to IMDSv2-only for new agents as of February 14, 2026, and (per secondary reporting) the default role was later narrowed.
The agent did not break out of a blocked path; it made a request it was allowed to make, to an address it never needed for its job, then posted credentials out. When the role behind those credentials spans the region, one public agent becomes a door to other agents' code, chats and secrets.
ORIGINAL REPORTING & EVIDENCE