CVE-2026-89049: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Published Sep 10, 2026
·
Updated

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.

To remediate this issue, users should upgrade to version 3.3.4851.0 or later.

Affected Software

2 affected components
Amazon AWS Systems Manager Agent (SSM Agent)<3.3.4851.0
AWS Systems Manager Agent (SSM Agent)<3.3.4851.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Amazon AWS Systems Manager Agent (SSM Agent) to a version that resolves this vulnerability.

    Fixed in 3.3.4851.0

Event History

Sep 10, 2026
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Managed instances running SSM Agent versions earlier than 3.3.4851.0 on any platform are affected if their Session Manager port forwarding to remote hosts functionality can be used by an authenticated remote user.

2

What access does an attacker need?

An attacker needs authenticated remote access sufficient to use the Session Manager port forwarding capability. No user interaction is required, and exploitation uses a crafted destination host value with an alternate representation of a denied link-local address.

3

What could an attacker gain through successful exploitation?

The attacker may reach link-local endpoints despite the remote destination denylist, including endpoints that expose temporary IAM role credentials for the managed instance. Those credentials could allow the attacker to act outside the instance with the permissions assigned to that instance role.

4

What is the remediation?

Upgrade the SSM Agent to version 3.3.4851.0 or later. The issue affects versions before 3.3.4851.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203