What is CVE-2026-16796?
CVE-2026-16796 is an improper neutralization of argument delimiters in the 'install_packages()' method of AWS Bedrock AgentCore Python SDK. This may allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. The vulnerability affects versions before 1.18.1.
Azərbaycanca: CVE-2026-16796 AWS Bedrock AgentCore Python SDK-nin 'install_packages()' metodunda arqument ayırıcılarının düzgün neytrallaşdırılmamasıdır. Bu, uzaqdan autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış paket adı arqumentləri vasitəsilə Code Interpreter sandbox daxilində ixtiyari əmrlər icra etməyə imkan verə bilər. Zəiflik 1.18.1 versiyasından əvvəlki versiyalara təsir edir.
Related CVEs
link basis: same weakness class CWE-77
FAQ1
What versions of the AWS Bedrock AgentCore Python SDK are affected by the argument delimiter vulnerability in the 'install_packages()' method?
The vulnerability affects versions before 1.18.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.