AWS patched a server-side authorization bypass in Amazon Quick that let authenticated non-admin users access AI Chat Agents through direct API requests even when administrators had explicitly blocked that capability with custom permissions. Fog Security found that the restriction was enforced in the user interface but not in the backend Chat Agent API, creating a CWE-862 missing authorization flaw. Researchers showed that after AI features were disabled for users, intercepted requests could still reach the agent and return responses until AWS fixed the issue, after which the same requests returned 401 Unauthorized and AGENT_ACCESS_DENIED.
The exposure was limited to intra-account access, with no reported cross-tenant impact, but it affected the only granular control customers had for restricting Quick’s AI features because standard AWS IAM, SCP, and RCP controls did not apply. That raised concern because Amazon Quick can connect chat agents to enterprise data sources including Slack, Microsoft Teams, Outlook, CRMs, databases, and documents. Fog Security reported the bug through HackerOne on March 4, and AWS deployed fixes across regions by March 12, but researchers said AWS silently patched the issue, rated its severity as "none," and did not issue a public customer advisory; AWS later said the affected admin control was not actively used by customers during the vulnerable period.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Following public reporting, AWS clarified that the specific administrator control capability impacted by the bug was not actively used by customers during the period when server-side validation was missing. The statement came amid criticism that the flaw still bypassed the only available granular control for restricting Quick AI Chat Agent access.
Fog Security publicly disclosed the vulnerability, stating that Amazon Quick users blocked by administrators could still reach AI Chat Agents via the API before AWS fixed the issue. The disclosure also noted AWS had reportedly rated the issue severity as "none" and had not issued a public customer advisory.
AWS rolled out fixes for the missing server-side authorization checks between March 11 and March 12, 2026. After the patch, previously successful unauthorized Chat Agent requests returned 401 Unauthorized or AGENT_ACCESS_DENIED responses.
Fog Security submitted the authorization bypass vulnerability to AWS through HackerOne. The report described how UI-enforced restrictions could be bypassed because backend API requests were not validating the same custom permission controls.
Fog Security identified a missing server-side authorization check in Amazon Quick's Chat Agent API that let authenticated non-admin users bypass administrator-set custom permissions and access AI chat features through direct backend requests. The issue affected intra-account access controls and did not show evidence of cross-tenant exposure.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetheregister.com
Open sourcetheregister.com
Open sourcehelpnetsecurity.com
Open sourcefogsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.