Skip to finding
important · Cloud privilege — AWS

Restricted SSM port forwarding can be turned into the managed instance’s IAM role.

Affects

AWS Systems Manager Agent, endpoint-management software on EC2 instances, on-premises servers and other managed machines.

A permitted principal uses an equivalent link-local address representation to bypass the destination check, reach instance metadata and retrieve temporary role credentials.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026