CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
AWS Systems Manager ยท 2026-09-10
Actions
Technical Details
| Affected Versions | < 3.3.4851.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-89049 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update SSM Agent to version 3.3.4851.0 across all managed nodes to address the server-side request forgery issue (CVE-2026-89049) and restrict use of the AWS-StartPortForwardingSessionToRemoteHost document until the upgrade is complete.
For Platform Teams
Deploy the latest SSM Agent version 3.3.4851.0 to ensure the security patch for the server-side request forgery vulnerability (CVE-2026-89049) is applied, reducing the risk of unauthorized access to IAM role credentials.
For Executives
Implement the SSM Agent update to version 3.3.4851.0 to mitigate the server-side request forgery vulnerability (CVE-2026-89049) and protect sensitive IAM role credentials from unauthorized access.