Sensitive Information Exposure in AWS Tools for PowerShell from Amazon
CVE-2026-107783

6.7MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107783?

A vulnerability has been identified in AWS Tools for PowerShell, where sensitive information, including an IAM user's cleartext AWS Management Console password, may be logged in command output and log artifacts. This occurs in versions prior to 5.0.306. Local users can exploit these logs to recover passwords, potentially compromising the security of AWS accounts. It is recommended to upgrade to version 5.0.306 or later and to review PowerShell transcripts and log stores for previously logged credentials. If compromised passwords are found, rotating those IAM console passwords is essential.

Affected Version(s)

aws-tools-for-powershell 0 <= 5.0.305

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.