{"id":"CVE-2026-107322","title":"An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a c…","summary":"An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a c…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-184"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:17:31.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107322","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-130-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/agent-plugins/commit/8b13a503746a4ebb0402b936645163224058bde3","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/agent-plugins/pull/232","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.184Z","slug":"CVE-2026-107322","body":"## Overview\n\nAn incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context.\n\n\n\nTo remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}