← Terug naar overzicht

CVE-2026-81849 is a path traversal vulnerability (CWE-22) in the aws:downloadContent plugin of amazon-ssm-agent versions prior to 3.3.4515.0. An authenticated remote user with restricted ssm:SendCommand permissions limited to the AWS-DownloadContent document can exploit crafted S3 object keys to write arbitrary files outside the intended download directory with root privileges. This could lead to arbitrary code execution as root if sensitive system files are overwritten. The vulnerability requires the attacker to already have some level of AWS IAM access, reducing but not eliminating the risk. Amazon has issued a security bulletin and released a patched version. Remediation requires upgrading amazon-ssm-agent to version 3.3.4515.0 or later. The issue affects AWS Systems Manager managed instances across all platforms running the vulnerable agent version.

Affected products

  • AWS Systems Manager
  • amazon-ssm-agent

Related CVE's

  • CVE-2026-81849

Categories

  • Cloud & Virtualization
  • Identity & Access