Command Injection Vulnerability in Amazon Agent Plugins for AWS Databases
CVE-2026-107322

8.5HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107322?

An incomplete list of disallowed inputs in the Amazon Agent Plugins for the AWS databases-on-aws plugin prior to version 1.7.1 can expose systems to command injection attacks. A remote, unauthenticated actor could exploit this vulnerability by crafting specific values for database commands, potentially allowing them to execute arbitrary operating system commands on the host running the plugin. It is crucial for users to upgrade to version 1.7.1 or later and ensure that the updated plugin is properly active in every environment where it is deployed to mitigate this risk.

Affected Version(s)

databases-on-aws 0 < 1.7.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.