Local Code Execution Vulnerability in AWS FPGA Development Kit
CVE-2026-85028

7.3HIGH

Key Information:

Vendor

Aws

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85028?

A vulnerability exists in the FPGA management tool installation component of the AWS FPGA Development Kit. This issue arises from the creation of a temporary file in a directory with insecure permissions, allowing local users to potentially execute arbitrary code with elevated privileges. The risk is particularly concerning as crafted shell content can be placed in a world-writable temporary directory, which the installation process reads after escalating its privileges. To mitigate this vulnerability, it is essential to upgrade to version 2.3.4 or later.

Affected Version(s)

aws-fpga 0 < 2.3.4

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.