Threat Advisory

AWS CLI Vulnerability Discloses Credentials Due to Weak Privilege Settings

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability, identified as CVE-2026-13769 with a CVSS score of 6.8, exists in the AWS CLI on Unix-like systems due to overly permissive file permissions created by certain subcommands, allowing other local users on the same host to read sensitive credentials. This flaw can be exploited through the environment where the AWS CLI is being executed, requiring low-privileged local access and no user interaction, resulting in high confidentiality impact but no integrity or availability impact. The vulnerability can be mitigated by upgrading to the latest version of the AWS CLI.

RECOMMENDATION:

We strongly recommend you update awscli to below version: https://github.com/aws/aws-cli/tags[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability, identified as CVE-2026-13769 with a CVSS score of 6.8, exists in the AWS CLI on Unix-like systems due to overly permissive file permissions created by certain subcommands, allowing other local users on the same host to read sensitive credentials. This flaw can be exploited through the environment where the AWS CLI is being executed, requiring low-privileged local access and no user interaction, resulting in high confidentiality impact but no integrity or availability impact. The vulnerability can be mitigated by upgrading to the latest version of the AWS CLI.

RECOMMENDATION:

We strongly recommend you update awscli to below version: https://github.com/aws/aws-cli/tags[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu