- Description
- A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
- Source
- ff89ba41-3aa1-4d27-914a-91399e9639e5
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- ff89ba41-3aa1-4d27-914a-91399e9639e5
- CWE-918
- Hype score
- Not currently trending
AWS disclosed SSRF flaw CVE-2026-89049 in SSM Agent port forwarding. Attackers with forwarding rights can bypass link-local deny lists and steal IAM role credentials from managed instances. Fixed in agent 3.3.4851.0 released 13 July 2026. #ThreatIntel #CVE #AWSSecurity
@WorldCyberNewsX
14 Sept 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
AWS SSM Agent の脆弱性(CVE-2026-89049) の被害があったかどうかを CloudTrail で確認する方法|nishikawa https://t.co/fjbHdDbJVw #zenn
@yousukezan
14 Sept 2026
340 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-68487 CVE-2026-68488 CVE-2026-89049 CVE-2026-89094 CVE-2026-52098 ..🧵👇
@exploitgrid
11 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes