CVE-2026-89049: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.
To remediate this issue, users should upgrade to version 3.3.4851.0 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon AWS Systems Manager Agent (SSM Agent)to a version that resolves this vulnerability.Fixed in 3.3.4851.0
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Managed instances running SSM Agent versions earlier than 3.3.4851.0 on any platform are affected if their Session Manager port forwarding to remote hosts functionality can be used by an authenticated remote user.
What access does an attacker need?
An attacker needs authenticated remote access sufficient to use the Session Manager port forwarding capability. No user interaction is required, and exploitation uses a crafted destination host value with an alternate representation of a denied link-local address.
What could an attacker gain through successful exploitation?
The attacker may reach link-local endpoints despite the remote destination denylist, including endpoints that expose temporary IAM role credentials for the managed instance. Those credentials could allow the attacker to act outside the instance with the permissions assigned to that instance role.
What is the remediation?
Upgrade the SSM Agent to version 3.3.4851.0 or later. The issue affects versions before 3.3.4851.0.