Threats Tagged 'cve-2026-89049'
View all threats tagged with 'cve-2026-89049'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-89049'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-89049 is a server-side request forgery (SSRF) vulnerability in the AWS Systems Manager Agent's Session Manager port forwarding functionality. An authenticated user with port-forwarding permission can bypass the remote destination denylist due to improper validation of equivalent address representations. This allows reaching link-local endpoints and potentially obtaining the managed instance's temporary IAM role credentials, enabling actions with those permissions from outside the instance. The vulnerability affects all versions of the SSM Agent prior to 3.3.4851.0. AWS has released version 3.3.4851.0 to address this issue. Until upgraded, restricting the use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping IAM permissions is recommended. Join the discussion | AWS Security Bulletins | 09/10/2026, 18:44:24 UTC Added: 09/10/2026, 19:00:32 UTC |
Showing 1 to 1 of 1 result