CVE-2026-7791: High severity Amazon Web Services Amazon WorkSpaces for Windows vulnerability
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7791?
CVE-2026-7791 is rated as a high severity vulnerability due to its potential for privilege escalation and unauthorized access.
How do I fix CVE-2026-7791?
To fix CVE-2026-7791, update Amazon WorkSpaces for Windows to version 2.6.2034.0 or later.
Who is affected by CVE-2026-7791?
CVE-2026-7791 affects all users of Amazon WorkSpaces for Windows versions prior to 2.6.2034.0.
What is the impact of CVE-2026-7791?
The impact of CVE-2026-7791 allows local non-admin authenticated users to bypass file system permission protections and place arbitrary files.
Is CVE-2026-7791 exploitable remotely?
CVE-2026-7791 is not exploitable remotely as it requires local access to the affected system.