CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Bulletin ID: 2026-107-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/10/2026 11:30 AM PDT

AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port forwarding to remote hosts. We identified CVE-2026-89049, a server-side request forgery issue in the remote-host port forwarding functionality. Due to improper validation of equivalent address representations, an authenticated user with port-forwarding permission could bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the managed instance's temporary IAM role credentials and acting with that role's permissions from outside the instance.

Impacted versions: < 3.3.4851.0 (all versions supporting remote-host port forwarding)

This issue has been addressed in SSM Agent version 3.3.4851.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Until the agent is upgraded, restrict use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping ssm:StartSession IAM permissions and SSM document permissions so that untrusted principals cannot start remote-host port-forwarding sessions.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 15, 2026 20:57
Versions
2 recorded
Identity
479bf224041ffe76607e77b4e68e4c5db06e11b8

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.