---
id: CVE-2026-89049
title: >-
  Server-side request forgery in the Session Manager port forwarding
  functionality in AWS Systems Manager Agent
summary: >-
  A server-side request forgery issue due to improper validation of equivalent
  address representations in the port forwarding to remote hosts functionality
  in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all
  platforms …
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-918
  - CWE-1289
vendor: AWS
product: Amazon SSM Agent
affected:
  - amazon_ssm_agent < 3.3.4851.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T18:57:35.732836Z'
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T18:57:53.315Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-89049'
references:
  - url: 'https://github.com/aws/amazon-ssm-agent/releases/tag/3.3.4851.0'
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-107-aws/'
  - url: >-
      https://github.com/aws/amazon-ssm-agent/security/advisories/GHSA-w9jw-h72g-6hxc
tags:
  - cve.org
epss: 0.00662
epssPercentile: 0.49463
ingestedAt: '2026-09-11T16:45:48.026Z'
---

## Overview

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.



To remediate this issue, users should upgrade to version 3.3.4851.0 or later.

## Affected

- `amazon_ssm_agent < 3.3.4851.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
