“We discovered that agents deployed through AgentCore could access their instance’s IMDS endpoints,”
Anyone who could chat with the agent could ask it for the cloud credentials. AWS closed the report as “informative” and called it documented behavior. The excess permissions were still there six months after disclosure. Amazon says exploitation needs developer error, which is what every cloud vendor says about its own defaults.
