OS Command Injection in log4j-patch for Amazon Linux
CVE-2026-85656

8.5HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85656?

An OS command injection vulnerability exists in the log4j-cve-2021-44228-hotpatch for Amazon Linux, allowing local users to execute arbitrary commands with root privileges. This occurs through a Java process that has embedded newline characters in its executable path, potentially leading to unauthorized access and system compromise. Users of affected versions are advised to apply the latest patch to mitigate risks.

Affected Version(s)

log4j-cve-2021-44228-hotpatch 0 < 1.3-9.amzn2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.