CVE-2026-107322
Awaiting Analysis Awaiting Analysis - Queue

Remote Code Execution in Amazon Agent Plugins

Vulnerability report for CVE-2026-107322, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: AMZN

Description

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aws databases-on-aws 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an incomplete list of disallowed inputs in Amazon Agent Plugins for the AWS databases-on-aws plugin before version 1.7.1. A remote unauthenticated attacker could exploit this to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context.

Detection Guidance

To detect this vulnerability, check the version of the databases-on-aws plugin. If it is version 1.0.0 through 1.7.0, the system is vulnerable. Run commands like 'aws --version' or inspect plugin files for version info. Verify if the helper processes crafted database commands by monitoring logs for unexpected shell command executions or file operations.

Impact Analysis

An attacker could gain control over the host system running the vulnerable plugin, potentially leading to unauthorized access, data theft, or further compromise of connected systems. This could disrupt operations and expose sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with data protection standards.

Mitigation Strategies

Upgrade to databases-on-aws plugin version 1.7.1 or later and verify the updated plugin is active in each environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107322. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart