Amazon released a security update addressing a critical server-side request forgery vulnerability in the AWS Systems Manager Agent. This severe security flaw, tracked as CVE-2026-89049, allows authenticated attackers to bypass port-forwarding restrictions. Administrators must deploy the patched agent immediately to protect instance metadata and prevent cloud credential theft.
- CVE: CVE-2026-89049
- CVSS: 9.9 (Critical · CVSSv3)
- Product: AWS Amazon SSM Agent
- Affected: < 3.3.4851.0
- Impact: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
- Status: No confirmed exploitation yet
- Patched in: 3.3.4851.0
- EPSS: 0.4% (30-day)
- Action: Update to 3.3.4851.0 now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Thousands of cloud administrators use the AWS Systems Manager Agent to execute remote commands across vast fleets of EC2 instances. Therefore, vulnerabilities within this core component present massive risks to cloud infrastructure. An attacker who exploits this flaw can extract temporary IAM role credentials directly from the Instance Metadata Service. Consequently, they can use these stolen credentials to launch unauthorized AWS API calls from outside the targeted instance.
How the Attack Works
The vulnerability resides within the Session Manager port forwarding functionality. The agent typically employs a denylist to prevent users from forwarding tunnels to local network addresses. However, attackers can bypass this protection using equivalent address representations. The advisory states, “An authenticated user with permission to start remote-host port-forwarding sessions could bypass the destination denylist and reach link-local endpoints, primarily the Instance Metadata Service.” This allows the attacker to retrieve the active IAM role credentials. Currently, researchers have confirmed no active exploitation or public proof-of-concept exploits for this bug.
Affected Versions
This server-side request forgery vulnerability impacts all AWS Systems Manager Agent versions prior to 3.3.4851.0.
Patch and Mitigation Steps
Amazon resolved the issue in agent version 3.3.4851.0. Network administrators must upgrade their managed nodes to this release immediately. If immediate patching is impossible, administrators should restrict the ssm:StartSession IAM permissions to prevent untrusted principals from initiating remote-host port forwarding.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!