CVE-2026-87912

Source
https://cve.org/CVERecord?id=CVE-2026-87912
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87912.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-87912
Aliases
  • GHSA-2px6-hhjp-3g5x
Published
2026-09-10T15:42:11Z
Modified
2026-09-12T03:47:22Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
Details

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier.

To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-283",
        "CWE-341"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87912.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "1.0.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "1.1.0"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/aws/agent-toolkit-for-aws

Affected ranges

Type
GIT
Repo
https://github.com/aws/agent-toolkit-for-aws
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87912.json"