Description
A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.



To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Published: 2026-09-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to confidential source archives
Action: Patch
AI Analysis

Impact

A missing verification step in the AWS Security Agent plugin allows a remote attacker to retrieve the private source archive of a scanned workspace. The archive can contain credentials and full infrastructure state, leading to a confidentiality breach of user data. The flaw is tied to CWE-283 (Improper Authorization) and CWE-341 (Weak Random Number Generation).

Affected Systems

All installations of the AWS Security Agent plugin earlier than version 1.1.0 are vulnerable. The vulnerability exists in the aws-agents-for-devsecops toolchain where the S3 bucket name is derived not validated.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium impact severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector requires the attacker to know the account identifier and the pre-registered bucket name; once the target’s bucket is not under the user’s ownership the attacker can download the archive. No public exploitation reports are documented, so the immediate risk is moderate but mitigatable with configuration or software updates.

Generated by OpenCVE AI on September 10, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AWS Security Agent plugin to version 1.1.0 or later.
  • Verify that the scan output bucket in your account is owned by your own AWS account; detecting an unowned bucket can expose sensitive data.
  • If a bucket is found to be controlled by a third party, reconfigure or delete it so that the plugin uses only a bucket under your ownership.

Generated by OpenCVE AI on September 10, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:00:00 +0000


Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.
Title Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
First Time appeared Aws
Aws aws Security Agent Plugin
Weaknesses CWE-283
CWE-341
CPEs cpe:2.3:a:aws:aws_security_agent_plugin:1.0.0:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Security Agent Plugin
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Aws Aws Security Agent Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-10T16:41:12.092Z

Reserved: 2026-09-09T15:23:09.972Z

Link: CVE-2026-87912

cve-icon Vulnrichment

Updated: 2026-09-10T16:41:08.901Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:18:07.037

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-87912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:30:10Z

Weaknesses
  • CWE-283

    Unverified Ownership

  • CWE-341

    Predictable from Observable State