Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port for …

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
4572b2bb6d28e173e7e4705e0f67d1b2
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.