Path Traversal Vulnerability in Amazon SSM Agent Affects AWS Users
CVE-2026-81849
8.7HIGH
What is CVE-2026-81849?
An improper limitation of a pathname occurs in the aws:downloadContent plugin of the amazon-ssm-agent prior to version 3.3.4515.0. This vulnerability may allow an authenticated remote user, whose permissions are restricted to the AWS-DownloadContent document, to write arbitrary files outside of the intended download directory. By crafting specific object keys in the associated S3 source, these users could potentially overwrite sensitive files and execute arbitrary code as root. Users are advised to update to amazon-ssm-agent version 3.3.4515.0 or later to mitigate this risk.
Affected Version(s)
amazon-ssm-agent 0 < 3.3.4515.0
