{"id":"CVE-2026-85028","title":"Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root priv…","summary":"Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root priv…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-379"],"published":"2026-09-03","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:00:33.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85028","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-096-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-fpga/releases/tag/v2.3.4","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-fpga/security/advisories/GHSA-g4hc-wrmm-2x74","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd"],"epss":0.00173,"epssPercentile":0.05949,"ingestedAt":"2026-09-08T15:33:26.958Z","slug":"CVE-2026-85028","body":"## Overview\n\nCreation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.\n\n\n\nTo remediate this issue, users should upgrade to version 2.3.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}