VYPR

Amazon Ssm Agent

by AWS

CVEs (1)

  • CVE-2026-81849HigAug 28, 2026
    risk 0.57cvss 8.8epss

    Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary…