AI and data stack advisories

Severe, 6 weeks1905Projects319

1905 severe, 6 weeks · 319 projects

AWSAWS-2026-132

Insertion of sensitive information into log file in AWS Tools for PowerShell

AWS

CVE-2026-107783 · Published Oct 9, 2026

Medium5.9
No fix yet
AWS advisory

Bulletin ID: 2026-132-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 08:30 AM PDT Description: AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. Impacted versions: <= v5.0.305 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

SeverityOct 10Severity: Unrated to Medium
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Severity from
NVD

More AWS advisories

All AWS