important · Cloud privilege — AWS
Restricted SSM port forwarding can be turned into the managed instance’s IAM role.
Affects
AWS Systems Manager Agent, endpoint-management software on EC2 instances, on-premises servers and other managed machines.
A permitted principal uses an equivalent link-local address representation to bypass the destination check, reach instance metadata and retrieve temporary role credentials.
Detail and 3 sources
The fixed agent canonicalizes addresses and expands the denylist for credential endpoints.
Sources
Code / PoCServer-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent · Advisory · aws/amazon-ssm-agent · GitHubCode / PoCRelease Amazon SSM Agent - Release 3.3.4851.0 - 2026-07-13 · aws/amazon-ssm-agent · GitHubVendorCVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent