CVE-2026-13769 โ€“ Insecure file permissions in AWS CLI

Cli ยท 2026-08-20

Actions

Rate this issue

Technical Details

Affected Versions <=1.44.77 (v1), <=2.34.28 (v2)
Regions all
CVE IDs CVE-2026-13769
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update AWS CLI to versions 1.44.78 (v1) and 2.34.29 (v2) to address CVE-2026-13769, ensuring credential files are no longer world-readable and reducing security risks.

For Platform Teams

Deploy the updated AWS CLI versions across your environment to enhance security posture and prevent unauthorized access to sensitive credentials.

For Executives

Implement the latest AWS CLI updates to mitigate the risk of unauthorized access to credentials due to insecure file permissions, ensuring compliance and protecting sensitive data.

Source

View original AWS announcement โ†’

Related Cli Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.