CVE-2026-13769 – Insecure file permissions in AWS CLI

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-13769 – Insecure file permissions in AWS CLI

Bulletin ID: 2026-049-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/01/2026 11:45 AM PDT

The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials.

Impacted versions: <=1.44.77 (v1) AND <=2.34.28 (v2)

This issue has been addressed in AWS CLI v1 1.44.78 and AWS CLI v2 2.34.29. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 29, 2026 16:00
Versions
1 recorded
Identity
b45733c9486599cf4534d3023945b89e54f31012

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.