Skip to main content

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

0
Critical
Published: 09/10/2026 (09/10/2026, 18:44:24 UTC)
Source: AWS Security Bulletins

Description

CVE-2026-89049 is a server-side request forgery (SSRF) vulnerability in the AWS Systems Manager Agent's Session Manager port forwarding functionality. An authenticated user with port-forwarding permission can bypass the remote destination denylist due to improper validation of equivalent address representations. This allows reaching link-local endpoints and potentially obtaining the managed instance's temporary IAM role credentials, enabling actions with those permissions from outside the instance. The vulnerability affects all versions of the SSM Agent prior to 3.3.4851.0. AWS has released version 3.3.4851.0 to address this issue. Until upgraded, restricting the use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping IAM permissions is recommended.

Affected software

GitHub Actionsmore threats →ai
aws/amazon-ssm-agent
pkg:github/aws/amazon-ssm-agent
Affected versions
<3.3.4851.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 19:00:39 UTC

Technical Analysis

AWS Systems Manager Agent (SSM Agent) versions prior to 3.3.4851.0 contain a server-side request forgery vulnerability in the Session Manager port forwarding feature. The flaw arises from improper validation of equivalent address representations, allowing an authenticated user with port-forwarding permission to bypass the remote destination denylist. This enables access to link-local endpoints, potentially exposing the managed instance's temporary IAM role credentials. Exploitation could allow an attacker to act with the permissions of the instance's IAM role from outside the instance. AWS has fixed this vulnerability in SSM Agent version 3.3.4851.0 and recommends upgrading. As a temporary mitigation, restricting the use of the relevant SSM document by limiting IAM permissions is advised.

Potential Impact

An authenticated user with port-forwarding permission can bypass security controls to access link-local endpoints on the managed instance. This may lead to exposure of temporary IAM role credentials associated with the instance, allowing the attacker to perform actions with those permissions externally. This elevates the risk of unauthorized access and privilege escalation within AWS environments using vulnerable SSM Agent versions.

Mitigation Recommendations

Upgrade AWS Systems Manager Agent to version 3.3.4851.0 or later, which contains the official fix for this vulnerability. Until the upgrade is applied, restrict the use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping IAM permissions (ssm:StartSession) and SSM document permissions to prevent untrusted principals from initiating remote-host port-forwarding sessions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/","fetched":true,"fetchedAt":"2026-09-10T19:00:32.474Z","wordCount":216}

Threat ID: 6aa2fe50d29482f9abfdaf8c

Added to database: 09/10/2026, 19:00:32 UTC

Last enriched: 09/10/2026, 19:00:39 UTC

Last updated: 09/10/2026, 22:12:46 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses