logo

Amazon Quick Flaw Exposed Restricted AI Chat Agents to Unauthorized Users

ID: 34f31263-b0fe-5ca4-bf0c-e1c2cbd2ff4c

STIX ID: report--34f31263-b0fe-5ca4-bf0c-e1c2cbd2ff4c

Feed Name: Cyber Press

Threat Score
55/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: AnuPriya

...
...

Fog Security discovered that Amazon QuickSight’s AI Chat Agent enforced custom permissions only in the UI while the backend chat-agent API lacked server-side authorization, enabling basic-account users to send POST requests to the API and receive AI-generated responses despite being restricted. The flaw (CWE-862) could expose insights from internal datasets and undermine governance and compliance; Fog Security disclosed via HackerOne and AWS rolled out a fix within about a week, with the issue limited to the same AWS account and no cross-account data leakage reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.