Description
Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.



To remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.
Published: 2026-10-09
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A vulnerability in AWS Tools for PowerShell before version 5.0.306 causes the tool to write sensitive data into log files, specifically the cleartext AWS Management Console password of an IAM user. This flaw is a case of improper handling of sensitive information (CWE-532) and permits a local user executing PowerShell commands to recover a valid IAM console password from command output and log artifacts, thereby compromising the confidentiality of that account.

Affected Systems

The affected product is AWS AWS Tools for PowerShell, any installation of a version earlier than 5.0.306. The issue is limited to the AWS Tools for PowerShell component and does not affect other AWS services or products.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The likely attack vector is local execution – a malicious or compromised local user who can run PowerShell scripts has the ability to trigger the logging of sensitive credentials. Once the sensitive data is in logs, a local attacker can later retrieve it, potentially escalating privileges within the AWS account.

Generated by OpenCVE AI on October 9, 2026 at 17:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AWS Tools for PowerShell to version 5.0.306 or later
  • Examine PowerShell transcripts and log stores for any previously exposed IAM console passwords
  • Rotate all IAM console passwords that were potentially disclosed

Generated by OpenCVE AI on October 9, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. To remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.
Title Insertion of sensitive information into log file in AWS Tools for PowerShell
First Time appeared Aws
Aws aws-tools-for-powershell
Weaknesses CWE-532
CPEs cpe:2.3:a:aws:aws-tools-for-powershell:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws-tools-for-powershell
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Aws Aws-tools-for-powershell
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-09T15:55:48.360Z

Reserved: 2026-10-08T20:07:21.397Z

Link: CVE-2026-107783

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T16:17:24.820

Modified: 2026-10-09T16:33:39.007

Link: CVE-2026-107783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:30:08Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File