CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

AWS Systems Manager ยท 2026-09-10

Actions

Rate this issue

Technical Details

Affected Versions < 3.3.4851.0
Regions all
CVE IDs CVE-2026-89049
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update SSM Agent to version 3.3.4851.0 across all managed nodes to address the server-side request forgery issue (CVE-2026-89049) and restrict use of the AWS-StartPortForwardingSessionToRemoteHost document until the upgrade is complete.

For Platform Teams

Deploy the latest SSM Agent version 3.3.4851.0 to ensure the security patch for the server-side request forgery vulnerability (CVE-2026-89049) is applied, reducing the risk of unauthorized access to IAM role credentials.

For Executives

Implement the SSM Agent update to version 3.3.4851.0 to mitigate the server-side request forgery vulnerability (CVE-2026-89049) and protect sensitive IAM role credentials from unauthorized access.

Source

View original AWS announcement โ†’

Related AWS Systems Manager Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.