Path Traversal Vulnerability in Amazon SSM Agent Affects AWS Users
CVE-2026-81849

8.7HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
28 August 2026

What is CVE-2026-81849?

An improper limitation of a pathname occurs in the aws:downloadContent plugin of the amazon-ssm-agent prior to version 3.3.4515.0. This vulnerability may allow an authenticated remote user, whose permissions are restricted to the AWS-DownloadContent document, to write arbitrary files outside of the intended download directory. By crafting specific object keys in the associated S3 source, these users could potentially overwrite sensitive files and execute arbitrary code as root. Users are advised to update to amazon-ssm-agent version 3.3.4515.0 or later to mitigate this risk.

Affected Version(s)

amazon-ssm-agent 0 < 3.3.4515.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.