CVE-2026-107783
Awaiting Analysis Awaiting Analysis - Queue

Insertion of Sensitive Information into Log File in AWS Tools for PowerShell

Vulnerability report for CVE-2026-107783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: AMZN

Description

Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. To remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
AWS aws-tools-for-powershell 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves AWS Tools for PowerShell versions before 5.0.306 where an IAM user's cleartext AWS Management Console password could be logged in plaintext. This occurs when using cmdlets with -WhatIf or -Confirm parameters that handle sensitive data, exposing the password in command output or logs.

Detection Guidance

Check PowerShell command history and transcript logs for instances where -WhatIf or -Confirm parameters were used with sensitive cmdlets. Review logs for any cleartext AWS Management Console passwords in output files or logs.

Impact Analysis

Local users with access to PowerShell logs or command history could recover the exposed password and gain unauthorized access to the AWS Management Console. This could lead to data breaches, unauthorized resource usage, or other malicious activities depending on the user's permissions.

Compliance Impact

This vulnerability could violate compliance requirements that mandate protection of sensitive authentication data, such as GDPR's data protection principles or HIPAA's safeguards for protected health information. Unauthorized access risks may lead to regulatory penalties or data exposure incidents.

Mitigation Strategies

Upgrade AWS Tools for PowerShell to version 5.0.306 or later. Avoid using -WhatIf or -Confirm parameters with sensitive cmdlets in vulnerable versions. Rotate any IAM console passwords that may have been exposed in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart