CVE-2026-89049 is a server-side request forgery vulnerability in AWS Systems Manager Agent versions before 3.3.4851.0 on all platforms. The remote-host Session Manager port-forwarding functionality improperly validates equivalent representations of destination addresses. An authenticated principal can supply an alternate representation of a denylisted link-local address, bypassing the remote-destination denylist and causing the managed instance to connect to otherwise restricted link-local services.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical SSRF and unsafe-equivalent-input-validation flaw in the AWS Systems Manager Agent remote-host port-forwarding feature. An authenticated principal permitted to start a remote-host port-forwarding session can bypass the agent's link-local address denylist through alternative address representations, potentially reaching the EC2 Instance Metadata Service and obtaining IAM instance-profile credentials.
A critical SSRF and improper input-validation vulnerability in AWS Systems Manager (SSM) Agent's remote-host port-forwarding capability. Alternate representations of link-local addresses can bypass its denylist, potentially allowing an authenticated user permitted to start a Session Manager remote-host port-forwarding session to access EC2 Instance Metadata Service credentials and then act with the EC2 instance IAM role's AWS permissions.
An authenticated server-side request forgery vulnerability in Amazon AWS Systems Manager Agent port forwarding. Alternate representations of denied link-local IP addresses can bypass the remote-destination denylist, potentially exposing a managed instance's temporary IAM credentials and enabling actions under that instance role.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.