Amazon Ssm Agent Amazon Ssm Agent

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazon Ssm Agent.

By the Year

In 2026 there have been 1 vulnerability in Amazon Ssm Agent with an average score of 8.7 out of ten. Amazon Ssm Agent did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 8.70
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 7.00

It may take a day or so for new Amazon Ssm Agent vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon Ssm Agent Security Vulnerabilities

Path Traversal in aws:downloadContent of amazon-ssm-agent <3.3.4515.0
CVE-2026-81849 8.7 - High - August 28, 2026

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is directed to retrieve. This issue may lead to arbitrary code execution as root if specific sensitive files are overwritten. To remediate this issue, customers should upgrade amazon-ssm-agent to version 3.3.4515.0 or later.

Relative Path Traversal

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which
CVE-2022-29527 7 - High - April 20, 2022

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.

Race Condition

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazon Ssm Agent or by Amazon? Click the Watch button to subscribe.

Amazon
Vendor

subscribe