Remote Access Vulnerability in AWS Security Agent Plugin by Amazon
CVE-2026-87912
5.1MEDIUM
What is CVE-2026-87912?
A flaw in the AWS Security Agent plugin allows attackers to potentially access sensitive data stored in a misconfigured S3 bucket. This vulnerability arises due to the absence of proper ownership verification for S3 buckets associated with the AWS Security Agent. As a result, adversaries could exploit this misconfiguration to retrieve private source archives that may contain critical credentials and infrastructure state information. To mitigate this risk, users are advised to upgrade to version 1.1.0 and ensure that their scan output bucket is secure and owned by their account, as upgrading will not affect buckets already registered by third parties.
Affected Version(s)
AWS Security Agent plugin 1.0.0
