CVE-2026-18655CWE-923

CVE-2026-18655

Medium · published August 4, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
16.6
In the wild
Unconfirmed
What it is

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.

To remediate this issue, users should upgrade to version 2.0.24.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00252 · 16.6th percentile
Weakness
CWE-923 · Improper Restriction of Communication Channel to Intended Endpoints
Published
2026-08-04T00:17Z
References (3)
EPSS history
Timeline
  • 03 AUG 19:04Z
    Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
    cvelistv5