Remote Access Vulnerability in AWS Security Agent Plugin by Amazon
CVE-2026-87912

5.1MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
10 September 2026

What is CVE-2026-87912?

A flaw in the AWS Security Agent plugin allows attackers to potentially access sensitive data stored in a misconfigured S3 bucket. This vulnerability arises due to the absence of proper ownership verification for S3 buckets associated with the AWS Security Agent. As a result, adversaries could exploit this misconfiguration to retrieve private source archives that may contain critical credentials and infrastructure state information. To mitigate this risk, users are advised to upgrade to version 1.1.0 and ensure that their scan output bucket is secure and owned by their account, as upgrading will not affect buckets already registered by third parties.

Affected Version(s)

AWS Security Agent plugin 1.0.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

glow.io
.