CVE-2026-89049

Public on 2026-09-10
Modified on 2026-09-28
Description
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.



To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Severity
Critical severity
Critical
See what this means
CVSS v3 Base Score
9.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-ssm-agent Pending Fix
Amazon Linux 2023 amazon-ssm-agent Pending Fix
Amazon Linux 2027 Preview amazon-ssm-agent Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H