Skip to content
AWSAWS-2026-049

Insecure file permissions in AWS CLI

Medium5.5CVE-2026-13769 · Published Sep 22, 2026

Bulletin ID:  2026-049-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials. Impacted versions:   Resolution: This issue has been addressed in AWS CLI v1 1.44.78 and AWS CLI v2 2.34.29 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. References: CVE-2026-13769 GHSA-wfp6-f47h-hxc3 Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to Medium
Details and references

Bulletin ID:  2026-049-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials. Impacted versions:   Resolution: This issue has been addressed in AWS CLI v1 1.44.78 and AWS CLI v2 2.34.29 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. References: CVE-2026-13769 GHSA-wfp6-f47h-hxc3 Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-049-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-13769 – Insecure file permissions in AWS CLI Bulletin ID:  2026-049-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials. Impacted versions:   Resolution: This issue has been addressed in AWS CLI v1 1.44.78 and AWS CLI v2 2.34.29 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. References: CVE-2026-13769 GHSA-wfp6-f47h-hxc3 Please email  aws-security@amazon.com  with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.", "items": [ { "name": "Learn", "linkURL": "", "items": [ { "heading": "What Is AWS?", "linkURL": "/what-is-aws/?nc1=f_cc" }, { "heading": "What Is Cloud Computing?", "linkURL": "/what-is-cloud-computing/?nc1=f_cc" }, { "heading": "What Is Agentic AI?", "linkURL": "/what-is/agentic-ai/?nc1=f_cc" }, { "heading": "Cloud Computing Concepts Hub", "linkURL": "/what-is/?nc1=f_cc" }, { "heading": "AWS Cloud Security", "linkURL": "/security/?nc1=f_cc" }, { "heading": "What's New", "linkURL": "/new/?nc1=f_cc" }, { "heading": "Blogs", "linkURL": "/blogs/?nc1=f_cc" }, { "

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.