CVE-2026-107322: OS command injection in Amazon Agent Plugins for AWS databases-on-aws
An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context.
To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Agent Plugins for AWS databases-on-awsto a version that resolves this vulnerability.Fixed in 1.7.1 - Operational
Verify that the updated databases-on-aws plugin is active in each environment where it is used
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the Amazon databases-on-aws plugin before version 1.7.1 are affected where the plugin is used. The vulnerable command execution occurs on the host running the helper.
What does exploitation require?
The issue can be triggered by a remote unauthenticated actor using a crafted database command value introduced in the agent context. User interaction is required according to the supplied severity vector.
What should teams do to remediate the issue?
Upgrade the databases-on-aws plugin to version 1.7.1 or later. Verify that the updated plugin is active in every environment where the plugin is used.