Skip to content
AWSAWS-2026-107

Server-side request forgery in the Session Manager port forwarding functionality in AWS...

UnratedCVE-2026-89049 · Published Sep 10, 2026

Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port forwarding to remote hosts. We identified CVE-2026-89049, a server-side request forgery issue in the remote-host port forwarding functionality. Due to improper validation of equivalent address representations, an authenticated user with port-forwarding permission could bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the managed instance's temporary IAM role credentials and acting with that role's permissions from outside the instance. Impacted versions: < 3.3.4851.0 (all versions supporting remote-host port forwarding) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.