Skip to finding
important · Privilege — AWS

Delegated SSM port forwarding can expose a managed instance’s IAM role credentials.

Affects

AWS Systems Manager Agent, management software running on EC2 instances, on-premises servers, and other managed nodes.

A permitted port-forwarding user can encode a link-local address in a form the agent’s denylist misses, tunnel to metadata, and use the retrieved instance-profile credentials outside the node.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026