Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions

AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions

Posted on September 14, 2026 By CWS

A serious security flaw in the AWS Systems Manager Agent has been identified, potentially allowing authenticated attackers to circumvent port-forwarding restrictions and access sensitive local services. The vulnerability specifically affects the Amazon EC2 Instance Metadata Service.

Details of the Security Flaw

This vulnerability, labeled as CVE-2026-89049, impacts Amazon SSM Agent versions prior to 3.3.4851.0. The issue has been resolved in subsequent updates, with version 3.3.4851.0 containing the necessary fixes. The AWS Systems Manager Agent facilitates remote management, including Run Command and Session Manager, on Amazon EC2 instances, on-premises servers, and virtual machines.

The Session Manager feature allows for secure port forwarding, enabling authorized users to establish protected connections from a managed instance to remote destinations without opening inbound network ports. The flaw lies within the remote-host port-forwarding feature, particularly when utilizing the AWS-StartPortForwardingSessionToRemoteHost SSM document.

Technical Analysis and Implications

According to a GitHub advisory, the agent’s denylist protection can be bypassed due to inadequate validation of link-local address representations. Typically, link-local IP addresses are blocked to prevent exposure of internal cloud services. However, an attacker could exploit this vulnerability to navigate around these restrictions using alternative address representations.

The EC2 Instance Metadata Service, often accessed at IP address 169.254.169.254, could be a primary target. This service provides temporary credentials tied to the IAM role of an EC2 instance. Successfully exploiting this flaw may allow attackers to obtain these credentials and use them to make AWS API calls beyond the compromised environment, depending on the permissions associated with the instance’s IAM role.

Recommendations for Mitigation

The vulnerability is classified as a server-side request forgery (SSRF) due to improper validation of unsafe input. It has been rated as Critical, with a CVSS v3.1 score indicating that the flaw is exploitable over a network, requires low complexity, and can severely affect confidentiality, integrity, and availability.

Organizations should promptly upgrade to SSM Agent version 3.3.4851.0 or later. Additionally, AWS advises reviewing any forked or derivative builds to confirm they incorporate the necessary validation enhancements. Until updates are applied, access to the AWS-StartPortForwardingSessionToRemoteHost document should be restricted, and IAM permissions for ssm:StartSession should be carefully managed to prevent unauthorized session initiation.

Security teams are encouraged to audit Session Manager activities, assess IAM roles linked to EC2 instances, and enforce least-privilege principles on instance profiles. The default configuration of the Amazon SSM Agent includes a denylist for metadata and link-local endpoints, highlighting the importance of robust address validation mechanisms.

Cyber Security News Tags:Amazon SSM Agent, AWS, cloud computing, cloud security, CVE-2026-89049, Cybersecurity, EC2, IAM, IT management, metadata service, network security, port forwarding, Security, SSRF, Vulnerability

Post navigation

Previous Post: AI’s Double-Edged Sword: Innovation and Risk
Next Post: WordPress Automates Plugin Security Reviews to Prevent Risks

Related Posts

Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems Cyber Security News
Stealth Linux Rootkit Targets F5 BIG-IP Servers Stealth Linux Rootkit Targets F5 BIG-IP Servers Cyber Security News
Remote File Upload Vulnerability in Cisco Meeting Management Remote File Upload Vulnerability in Cisco Meeting Management Cyber Security News
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Cyber Security News
ServiceNow Updates Address Critical Security Vulnerabilities ServiceNow Updates Address Critical Security Vulnerabilities Cyber Security News
Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks
  • AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions
  • AI’s Double-Edged Sword: Innovation and Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Twitch Extension JeetBot Risks User Security
  • Critical Vulnerabilities in JFrog Artifactory Exploited
  • WordPress Automates Plugin Security Reviews to Prevent Risks
  • AWS Agent Flaw Allows Bypass of Port-Forwarding Restrictions
  • AI’s Double-Edged Sword: Innovation and Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark