Threat Advisory

AWS Systems Manager Agent Flaw Lets Attackers Bypass Port-Forwarding Restrictions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical server-side request forgery (SSRF) flaw, tracked as CVE-2026-89049 with a CVSS score of 9.8, allows authenticated attackers to bypass remote-host port-forwarding restrictions and access sensitive link-local services in the AWS Systems Manager Agent. The vulnerability affects versions earlier than 3.3.4851.0 and has been fixed in version 3.3.4851.0. An attacker must already have authenticated AWS access and permission to initiate a remote-host port-forwarding session, but successful exploitation could let that user route traffic to restricted link-local endpoints by using an alternative representation of a blocked destination address. The vulnerability is classified as improper validation of unsafe equivalent input, which can lead to the retrieval of instance profile credentials from the metadata service, enabling access to S3 buckets, Secrets Manager secrets, databases, Lambda functions, or other cloud resources with overly permissive roles. This flaw exists in the remote-host port-forwarding feature used through a specific AWS-StartPortForwardingSessionToRemoteHost document and can be exploited by an attacker who has already authenticated AWS access and permission to initiate a remote-host port-forwarding session. The effective impact depends on the permissions assigned to the instance’s IAM role, with overly permissive roles potentially enabling access to sensitive cloud resources.

RECOMMENDATIONS:

  • We recommend you to update Amazon SSM Agent to version 3.3.4851.0.
  • We recommend you to review forked or derivative builds of the agent to ensure they incorporate the validation fix.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical server-side request forgery (SSRF) flaw, tracked as CVE-2026-89049 with a CVSS score of 9.8, allows authenticated attackers to bypass remote-host port-forwarding restrictions and access sensitive link-local services in the AWS Systems Manager Agent. The vulnerability affects versions earlier than 3.3.4851.0 and has been fixed in version 3.3.4851.0. An attacker must already have authenticated AWS access and permission to initiate a remote-host port-forwarding session, but successful exploitation could let that user route traffic to restricted link-local endpoints by using an alternative representation of a blocked destination address. The vulnerability is classified as improper validation of unsafe equivalent input, which can lead to the retrieval of instance profile credentials from the metadata service, enabling access to S3 buckets, Secrets Manager secrets, databases, Lambda functions, or other cloud resources with overly permissive roles. This flaw exists in the remote-host port-forwarding feature used through a specific AWS-StartPortForwardingSessionToRemoteHost document and can be exploited by an attacker who has already authenticated AWS access and permission to initiate a remote-host port-forwarding session. The effective impact depends on the permissions assigned to the instance’s IAM role, with overly permissive roles potentially enabling access to sensitive cloud resources.

RECOMMENDATIONS:

  • We recommend you to update Amazon SSM Agent to version 3.3.4851.0.
  • We recommend you to review forked or derivative builds of the agent to ensure they incorporate the validation fix.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu