Description
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.



To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized execution with temporary IAM credentials via port forwarding bypass
Action: Patch immediately
AI Analysis

Impact

A server‑side request forgery flaw in Amazon AWS Systems Manager Agent allows an authenticated remote user to craft destination host values that use alternate representations of denied link‑local addresses. By bypassing the private link‑local endpoints and retrieve the instance's temporary IAM role credentials. The attacker can then act with those permissions from outside the instance, potentially accessing or modifying resources and data the role is allowed to control.

Affected Systems

AWS Systems Manager Agent (SSM Agent) versions earlier than 3.3.4851.0 on all supported platforms are affected. The vulnerability exists in the session manager port forwarding implementation of the agent.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must be authenticated with SSM permissions, the exploit requires valid credentials but can be carried out remotely by abusing the port‑forwarding feature. No public exploit has been reported, but the combination of authenticated access and the ability to obtain temporary IAM credentials presents a significant risk.

Generated by OpenCVE AI on September 10, 2026 at 22:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Amazon SSM Agent to version 3.3.4851.0 or later
  • Restrict the use of Session Manager port forwarding and limit SSM permissions to only those roles that require it
  • Configure network controls to block or monitor link‑local traffic that is not explicitly allowed

Generated by OpenCVE AI on September 10, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Title Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
First Time appeared Aws
Aws amazon Ssm Agent
Weaknesses CWE-1289
CWE-918
CPEs cpe:2.3:a:aws:amazon_ssm_agent:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws amazon Ssm Agent
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Aws Amazon Ssm Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-10T18:57:53.315Z

Reserved: 2026-09-10T16:58:08.584Z

Link: CVE-2026-89049

cve-icon Vulnrichment

Updated: 2026-09-10T18:57:49.503Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T19:17:42.373

Modified: 2026-09-10T19:44:21.980

Link: CVE-2026-89049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:45:18Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input

  • CWE-918

    Server-Side Request Forgery (SSRF)