CVE-2026-13769 – Insecure file permissions in AWS CLI
Cybersecurity Classified by Officially
CVE-2026-13769 – Insecure file permissions in AWS CLI
Bulletin ID: 2026-049-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/01/2026 11:45 AM PDT
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials.
Impacted versions: <=1.44.77 (v1) AND <=2.34.28 (v2)
This issue has been addressed in AWS CLI v1 1.44.78 and AWS CLI v2 2.34.29. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 29, 2026 16:00
- Versions
- 1 recorded
- Identity
b45733c9486599cf4534d3023945b89e54f31012