CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

Published 2026-09-10T18:44:24Z41c7df7bffb3ef5a4c79b40971ab0032956ae1e5dc9c4e654b53047c2f503900

Source metadata

Publication date
2026-09-10T18:44:24Z
Source identifier
479bf224041ffe76607e77b4e68e4c5db06e11b8
Public record ID
record:sha256:41c7df7bffb3ef5a4c79b40971ab0032956ae1e5dc9c4e654b53047c2f503900

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
41c7df7bffb3ef5a4c79b40971ab0032956ae1e5dc9c4e654b53047c2f503900
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent · Baitaphish