Amazon Quick authorization bypass let users reach blocked AI chat agents
ID: 07a9a0d3-03d9-5219-b1f7-0c0616558997
STIX ID: report--07a9a0d3-03d9-5219-b1f7-0c0616558997
Feed Name: Help Net Security
Fog Security discovered a missing server-side authorization (CWE-862) in Amazon Quick's Chat Agent API that allowed disabled chat agents to be invoked via direct API calls despite administrators setting custom permissions to block them. The issue was reported to AWS on March 4, 2026; AWS rolled out a fix to production regions on March 11–12, 2026, returning AGENT_ACCESS_DENIED errors after the patch. The impact was limited to intra-account policy bypass (no cross-tenant access observed), but the flaw undermined administrative controls and compliance assurances for organizations using Quick.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
