Description
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Published: 2026-09-04
Score: 8.5 High
EPSS: 1.1% Low
KEV: No
Impact: Local privilege escalation via OS command injection
Action: Patch Immediately
AI Analysis

Impact

An OS command injection flaw exists in the Amazon log4j-cve-2021-44228-hotpatch package used by Amazon Linux. The flaw allows a local user to cause a Java process to execute an arbitrary command with root privileges when the process’s executable path contains newline characters. This vulnerability falls under CWE‑78 and can be exploited to run any code, giving the attacker full control over the affected system.

Affected Systems

The affected package is Amazon:log4j-cve-2021-44228-hotpatch, all releases before 1.3-9 on Amazon Linux. Users on earlier versions are at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while the EPSS score is 1% and the issue is not listed in the CISA KEV catalog. The vulnerability requires local access and a Java process whose executable path contains embedded newlines, so an attacker must already have some local foothold. Nonetheless, the potential for arbitrary root‑level command execution makes the risk significant for impacted hosts.

Generated by OpenCVE AI on September 5, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the log4j‑cve‑2021‑44228‑hotpatch package to version 1.3‑9 or later as detailed in the Amazon Linux advisory.
  • Reconfigure Java applications to avoid using executable paths that could contain newline characters or other control characters, and run them with the least privileges necessary.
  • Audit system logs for unexpected command executions and monitor for suspicious process creation tied to Java applications.

Generated by OpenCVE AI on September 5, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Title OS command injection in Amazon log4j-cve-2021-44228-hotpatch
First Time appeared Amazon
Amazon log4j-cve-2021-44228-hotpatch
Weaknesses CWE-78
CPEs cpe:2.3:a:amazon:log4j-cve-2021-44228-hotpatch:*:*:*:*:*:*:*:*
Vendors & Products Amazon
Amazon log4j-cve-2021-44228-hotpatch
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Amazon Log4j-cve-2021-44228-hotpatch
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-04T17:49:26.880Z

Reserved: 2026-09-04T13:13:08.811Z

Link: CVE-2026-85656

cve-icon Vulnrichment

Updated: 2026-09-04T17:49:22.697Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T18:18:06.133

Modified: 2026-09-08T14:00:33.017

Link: CVE-2026-85656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T16:00:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')