AWS Security Digest·Week 35 of 2026·Aug 24-30, 2026·1 item

    One CVE, Root Privileges: SSM Agent's Path Traversal Bug

    A genuinely quiet week closes with a single but serious finding: a path traversal flaw in the SSM Agent's download-content plugin can be abused to write files - with root privileges - outside the intended directory.

    In this issue1high

    CVEs & Vulnerabilities

    1 item
    $ cat /var/reports/CVE_REPORT.txt
    high/CVE/

    CVE-2026-81849: Path Traversal in SSM Agent's Download-Content Plugin

    The aws:downloadContent plugin in amazon-ssm-agent improperly limits pathnames to a restricted directory. An authenticated remote user holding ssm:SendCommand permission scoped to the AWS-DownloadContent document can direct the agent to fetch a crafted S3 object whose key traverses outside the intended download directory, writing arbitrary files with root privileges - potentially leading to code execution if sensitive system files are overwritten. Affects SSM Agent 2.0.767.0 through 3.3.4364.0; fixed in 3.3.4515.0.

    Affected
    • amazon-ssm-agent 2.0.767.0-3.3.4364.0
    Fixed In
    • amazon-ssm-agent 3.3.4515.0
    Systems Manager

    Key Takeaway

    1 item
    $ cat WEEKLY_SUMMARY.md

    The blast radius here depends entirely on how tightly you scope ssm:SendCommand - if any principal beyond a small break-glass set can invoke AWS-DownloadContent, treat this as urgent. Everyone else should still patch to 3.3.4515.0 on the normal cycle; this is a light week otherwise.

    Filed Under
    Systems ManagerCVEPath Traversal

    Need Custom Security Briefings?

    These weekly digests are a starting point. Contact us for tailored threat briefings, security assessments, and architectural guidance for your AWS environment.