Skip to content
AWSAWS-2026-025

Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent

UnratedCVE-2026-7791 · Published May 4, 2026 · updated Sep 25, 2026

Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT   Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified  CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions:  Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with ...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT   Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified  CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions:  Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-025-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT   Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified  CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions:  Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc.

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.