Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3....

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
6fcb9624f2297f2f52f451136955753a
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.