CVE-2026-13769 โ Insecure file permissions in AWS CLI
Cli ยท 2026-08-20
Actions
Technical Details
| Affected Versions | <=1.44.77 (v1), <=2.34.28 (v2) |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-13769 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update AWS CLI to versions 1.44.78 (v1) and 2.34.29 (v2) to address CVE-2026-13769, ensuring credential files are no longer world-readable and reducing security risks.
For Platform Teams
Deploy the updated AWS CLI versions across your environment to enhance security posture and prevent unauthorized access to sensitive credentials.
For Executives
Implement the latest AWS CLI updates to mitigate the risk of unauthorized access to credentials due to insecure file permissions, ensuring compliance and protecting sensitive data.
Source
Related Cli Updates
- CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows (2026-08-20)
- CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI (2026-08-20)
- AWS Client VPN now supports CLI, administration controls, and faster connections (2026-08-13)
- CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows (2026-08-04)
- AWS Client VPN extends availability to four additional AWS Regions (2026-07-09)