CVE-2026-13769Medium· 5.5▾ SunlitAWS CLI: Overly permissive File Permissions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.1%
0.1% → 0.2%
Last analysed / modified upstream
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. Certain CLI subcommands wrote credential and configuration files with world-readable permissions on Unix-like systems with a default umask, allowing other local users on the same host to read credentials.
On Unix-like systems with a default umask, the following AWS CLI subcommands wrote credential or configuration files with world-readable permissions (0644) instead of owner-only (0600):
aws codeartifact login
aws iam create-virtual-mfa-device
aws deploy register
Any other local user on the same host could read these files and obtain the credentials.
Impacted versions: <=1.44.77 (v1) AND <=2.34.28 (v2)
This issue has been addressed in AWS CLI v1 version 1.44.78 and AWS CLI v2 version 2.34.29. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
If you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to [email protected]. Please do not create a public GitHub issue.
awscli < 1.44.78Upgrade to a patched release:
awscli 1.44.78Connected by shared product, vendor, weakness, or advisory.
GHSA-747p-wmpv-9c78Medium· 5.9AWS CLI: cli_history database does not restrict file permissions on Unix systems
CVE-2026-18654Medium· 6.8AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
CVE-2018-13374Medium· 4.3A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connecti…
CVE-2026-10840High· 7.1A flaw was found in the OpenShift Pipelines operator
CVE-2026-0775High· 7.0npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
CVE-2026-24049High· 7.1wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427