CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
Ssm Agent ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 2.0.767.0 to 3.3.4364.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-81849 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the amazon-ssm-agent to version 3.3.4515.0 or later to address the path traversal vulnerability (CVE-2026-81849) and prevent potential arbitrary code execution.
For Platform Teams
Deploy the latest amazon-ssm-agent version 3.3.4515.0 to ensure systems are protected against the path traversal vulnerability and maintain secure operations.
For Executives
Implement the SSM Agent upgrade to version 3.3.4515.0 or later to mitigate the risk of arbitrary code execution due to the identified path traversal vulnerability.