Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent
UnratedCVE-2026-7791 · Published May 4, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions: Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with ...
Affected versions
Details and references
Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions: Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-025-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/04/2026 15:15 PM PDT Description: Amazon Skylight Workspace Config Service (slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspace Config Service's log file archival process. This issue impacts Amazon WorkSpaces customers using Windows WorkSpaces that have not opted-in to enable " Local Administrator Setting " on their directory. Impacted versions: Resolution: This issue has been addressed in 2.6.2034.0 version. We recommend upgrading to the latest version of the Amazon Skylight Workspace Config Service. Affected customers can self-service the update by rebooting impacted WorkSpaces. References: CVE-2026-7791 Acknowledgment: We would like to thank Cymulate for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc.
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 8 | Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver | Unrated | No fix yet |
| May 7 | Dirty Frag and other issues in Amazon Linux kernels | Unrated | No fix yet |
| May 6 | AWS: privilege escalation | Unrated | No fix yet |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer... | Unrated | No fix yet |