AWS Bedrock AgentCore 'Agent God Mode': over-broad default IAM let one agent compromise all others in the account
2026-aws-bedrock-agentcore-god-mode · 2026-04-08
Unit 42 showed that the AWS Bedrock AgentCore starter toolkit auto-generated IAM roles with wildcard resource access instead of least privilege. A single compromised agent could then reach every other agent in the same AWS account — pulling their container images, recovering memory IDs, reading and poisoning their conversation memories, and pivoting into higher-privileged code interpreters.
System
- Framework
- AWS Bedrock AgentCore (starter toolkit)
- Tools
- bedrock-agentcore, iam, ecr, code-interpreter
- Vendor
- Amazon Web Services
- Autonomy
- supervised-autonomous
Classification
- Primary class
- excessive-agency
- Chain
- excessive-agency/scope-creep → multi-agent-failure/cascade → data-exfiltration/via-tool
- Attack vector
- n-a
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
The AgentCore starter toolkit auto-created IAM roles granting wildcard resource access (arn:aws:bedrock-agentcore:*) rather than scoping to individual resources. Starting from one compromised agent, a researcher chained four primitives within the same AWS account: pulling other agents' container images from ECR, extracting their memory IDs from those images, reading and poisoning their conversation memories via wildcard GetMemory, and invoking higher-privileged code interpreters.
Root cause
Default IAM roles violated least privilege, giving each agent account-wide access to all agents' resources. With no per-agent isolation of images, memory, or interpreters, compromising one agent granted access to every other agent in the account.
Contributing factors
- Starter-toolkit defaults auto-generated wildcard IAM permissions instead of least privilege.
- Agents' container images, memory stores, and interpreters were not isolated per agent.
- Wildcard GetMemory permitted reading and poisoning other agents' conversation memories.
Detection
Discovered by Unit 42 at Palo Alto Networks (researcher Ori Hadad) and published on 2026-04-08 as a proof-of-concept technical demonstration.
Recovery
AWS updated documentation with warnings that the toolkit defaults are intended for development and testing and are unsuitable for production; no structural toolkit changes were disclosed.
Prevention
Scope agent IAM roles to individual resources (least privilege), not wildcards; isolate per-agent images, memory stores, and interpreters; do not ship broad-by-default roles for production; monitor for cross-agent resource access.
Blast radius
- Data
- A compromised agent could read and poison other agents' conversation memories and pull their container images and configuration across the AWS account. confidential
- User harm
- A proof-of-concept demonstration; no in-the-wild exploitation was reported. none-reported
- Scope
- all agents within the same AWS account using the toolkit defaults
- Reversibility
- reversible
References
- OWASP LLM
- LLM02 LLM06
- OWASP Agentic
- T3 T13
- MITRE ATLAS
- AML.T0024
- Related
- 2026-dialogflow-cx-rogue-agent 2026-google-adk-agent-privilege-escalation 2026-mind-viruses-multi-agent-propagation
- Tags
- multi-agent iam over-permissioning cross-agent-memory bedrock aws
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-aws-bedrock-agentcore-god-mode/
@misc{2026-aws-bedrock-agentcore-god-mode,
title = {AWS Bedrock AgentCore 'Agent God Mode': over-broad default IAM let one agent compromise all others in the account},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-aws-bedrock-agentcore-god-mode/}
}