agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

AWS Bedrock AgentCore 'Agent God Mode': over-broad default IAM let one agent compromise all others in the account

2026-aws-bedrock-agentcore-god-mode · 2026-04-08

Unit 42 showed that the AWS Bedrock AgentCore starter toolkit auto-generated IAM roles with wildcard resource access instead of least privilege. A single compromised agent could then reach every other agent in the same AWS account — pulling their container images, recovering memory IDs, reading and poisoning their conversation memories, and pivoting into higher-privileged code interpreters.

System

Framework
AWS Bedrock AgentCore (starter toolkit)
Tools
bedrock-agentcore, iam, ecr, code-interpreter
Vendor
Amazon Web Services
Autonomy
supervised-autonomous

Classification

Primary class
excessive-agency
Chain
excessive-agency/scope-creep → multi-agent-failure/cascade → data-exfiltration/via-tool
Attack vector
n-a
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

The AgentCore starter toolkit auto-created IAM roles granting wildcard resource access (arn:aws:bedrock-agentcore:*) rather than scoping to individual resources. Starting from one compromised agent, a researcher chained four primitives within the same AWS account: pulling other agents' container images from ECR, extracting their memory IDs from those images, reading and poisoning their conversation memories via wildcard GetMemory, and invoking higher-privileged code interpreters.

Root cause

Default IAM roles violated least privilege, giving each agent account-wide access to all agents' resources. With no per-agent isolation of images, memory, or interpreters, compromising one agent granted access to every other agent in the account.

Contributing factors

  • Starter-toolkit defaults auto-generated wildcard IAM permissions instead of least privilege.
  • Agents' container images, memory stores, and interpreters were not isolated per agent.
  • Wildcard GetMemory permitted reading and poisoning other agents' conversation memories.

Detection

Discovered by Unit 42 at Palo Alto Networks (researcher Ori Hadad) and published on 2026-04-08 as a proof-of-concept technical demonstration.

Recovery

AWS updated documentation with warnings that the toolkit defaults are intended for development and testing and are unsuitable for production; no structural toolkit changes were disclosed.

Prevention

Scope agent IAM roles to individual resources (least privilege), not wildcards; isolate per-agent images, memory stores, and interpreters; do not ship broad-by-default roles for production; monitor for cross-agent resource access.

Blast radius

Data
A compromised agent could read and poison other agents' conversation memories and pull their container images and configuration across the AWS account. confidential
User harm
A proof-of-concept demonstration; no in-the-wild exploitation was reported. none-reported
Scope
all agents within the same AWS account using the toolkit defaults
Reversibility
reversible

References

OWASP LLM
LLM02 LLM06
MITRE ATLAS
AML.T0024
Tags
multi-agent iam over-permissioning cross-agent-memory bedrock aws

Sources

Cite this incident

@misc{2026-aws-bedrock-agentcore-god-mode,
  title = {AWS Bedrock AgentCore 'Agent God Mode': over-broad default IAM let one agent compromise all others in the account},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-aws-bedrock-agentcore-god-mode/}
}