Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89049— Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Quick assessment

Affected
AWS Amazon SSM Agent
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这是一段关于 Amazon AWS Systems Manager (SSM) Agent 中服务器端请求伪造(SSRF)漏洞的官方描述。以下是该段落的中文翻译: 由于在 Amazon AWS Systems Manager Agent (SSM Agent) 的“端口转发至远程主机”功能中,对等效地址表示(equivalent address representations)的验证不当,导致服务器端请求伪造问题。在版本 3.3.4851.0 之前的所有平台上的 SSM Agent 可能存在此缺陷。 该漏洞允许经过

CVSS 9.9 · Critical

Possible ATT&CK Techniques 1 AI

T1071 · Application Layer Protocol

Affected Version Matrix 1

VendorProduct Version RangeStatus
AWS Amazon SSM Agent < 3.3.4851.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89049

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Source: CVE Program / CVE List V5
Vulnerability Description
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AWS Amazon SSM Agent 0 ~ 3.3.4851.0 -

II. Public POCs for CVE-2026-89049

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89049

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89049 (2)

Vendor Pages for CVE-2026-89049 (1)

Same Patch Batch · AWS · 2026-09-10 · 3 CVEs total

CVE-2026-87913 5.9 MEDIUM Missing S3 bucket ownership verification in the AWS Security Agent MCP server
CVE-2026-87912 5.9 MEDIUM Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-f

IV. Related Vulnerabilities

V. Comments for CVE-2026-89049

No comments yet


Leave a comment