MyPrivateClaw

AWS API MCP Server Patched for Security Policy Bypass CVE-2026-16584 | vulnerability-disclosure

The AWS API MCP Server contains CVE 2026 16584, patched in version 1.3.47.

Published on MyPrivateClaw

Jul 26, 2026, 4:10 PM UTC

Coverage date

Jul 24, 2026

Last updated

Jul 26, 2026, 4:10 PM UTC

News summary

The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands, including an optional user configured security policy. CVE 2026 16584 is a security policy bypass vulnerability where the per request policy check is silently skipped if the security policy enforcement data fails to initialize at server startup, bounded to configured security policy gate only. Affected versions are = 0.2.13 AND < 1.3.47 of awslabs.aws api mcp server, and the vulnerability has been patched in awslabs.aws api mcp server version 1.3.47. The vulnerability is classified as CWE 455 (Non exit on Failed Initialization) and was disclosed by independent security researcher Lav Kumar Vishwakarma through AWS's coordinated vulnerability disclosure process. The CVSS v4.0 base score for CVE 2026 16584 is 7.3, with…