AWS Latest Bulletins
Follow
CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
This bulletin addresses a critical security vulnerability in the AWS Systems Manager Agent (SSM Agent). The vulnerability, identified as CVE-2026-89049, is a server-side request forgery issue. It specifically affects the remote-host port forwarding functionality of the SSM Agent. The flaw arises from improper validation of equivalent address representations. An authenticated user with port-forwarding permissions can exploit this to bypass destination denylists. This bypass allows them to reach link-local endpoints. Exploitation could lead to the compromise of the managed instance's temporary IAM role credentials. The attacker could then impersonate the instance using those credentials. Versions of SSM Agent prior to 3.3.4851.0 are impacted, provided they support remote-host port forwarding. Users are strongly advised to consult the linked article for comprehensive details and remediation guidance.