Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Start by reviewing Systems Manager StartSession management events across every relevant AWS account and Region, then prioritize sessions using AWS-StartPortForwardingSessionToRemoteHost. Separately confirm the SSM Agent version on each managed node: CloudTrail records API activity, but it cannot by itself establish that the vulnerability was exploited or that instance-role credentials were exposed.

What CVE-2026-89049 affects

AWS security bulletin 2026-107-AWS, published September 10, 2026, describes a server-side request forgery flaw in SSM Agent’s Session Manager remote-host port-forwarding functionality. Improper validation of equivalent address representations could let an authenticated user with port-forwarding permission bypass the remote-destination denylist and reach link-local endpoints. One potential consequence is exposure of the managed instance’s temporary IAM role credentials; those credentials could then be used outside the instance with the role’s permissions.

AWS identifies SSM Agent versions earlier than 3.3.4851.0 as affected within the stated scope of versions supporting remote-host port forwarding. Version 3.3.4851.0 contains the fix; AWS recommends upgrading to the latest available release and patching forked or derivative code. The AWS-maintained GitHub advisory assigns the issue a CVSS v3 base score of 9.9. That score rates severity; it is not an estimate of affected customers or confirmed exploitation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Amazon Linux package advisories list separate package builds: amazon-ssm-agent-3.3.5226.0-1.amzn2 for Amazon Linux 2 and amazon-ssm-agent-3.3.5226.0-1.amzn2023 for Amazon Linux 2023. Package availability can change, so check the current repository and the advisory for the specific operating system before deciding how to update.

#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Search CloudTrail for StartSession activity

1. Cover the right accounts and Regions

Include every account and Region where managed nodes or Session Manager activity may exist. A single-Region trail covers only its configured Region; AWS recommends multi-Region trails to capture activity across Regions. Establish which accounts, Regions, and dates your available records actually cover before treating a search as comprehensive.

2. Filter Event history for the API call

  1. In the AWS console, open CloudTrail and select Event history.
  2. Filter for the Systems Manager event source and the StartSession event name. Systems Manager control-plane operations are logged as CloudTrail management events by default, and AWS specifically identifies StartSession as generating an event.
  3. Review each matching event record. Check the principal and role session, event time, Region, target, document name, request parameters, source IP, and any success or error details present.
  4. Inspect the raw record rather than assuming every field is populated. The StartSession API accepts a document name and parameters, but the fields shown can vary with the event shape.

3. Prioritize remote-host port forwarding

Give particular attention to use of AWS-StartPortForwardingSessionToRemoteHost and other evidence of remote-host port forwarding. AWS names this document in its interim mitigation guidance. A matching event is a lead for investigation, not proof that a denylist bypass occurred.

Correlate the event with session and security evidence

CloudTrail can identify recorded API-request context, including who made a request, when and from where it was made, and the target or document where those details were captured. Session Manager history can add the session ID, user, managed-node ID, start and end times, status, and configured session-log location; the console exposes more session details than the CLI history list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Evidence source What it can help establish Important limit
CloudTrail StartSession event Recorded request identity, time, source, and target or document when present. A session request alone does not show that the vulnerable address was used, the denylist was bypassed, or credentials were obtained.
Session Manager history Session ID, user, node, start and end times, status, and configured log location. Available detail depends on the history view and records retained.
Configured session data logs Session content where logging was enabled and the logs remain available. Logging is configured separately; do not assume session content exists.
IAM activity and host or network telemetry Corroborating activity that may help assess possible use of the instance role or activity on the managed node. Interpret it in context; no single source necessarily establishes the full exploit path.

Correlate suspicious sessions with IAM activity that could indicate use of the instance role and with relevant host or network telemetry. AWS notes that CloudTrail records session API calls, while actions inside a session that do not make API calls are not detected by EventBridge. Therefore, a CloudTrail event can establish that recorded API activity occurred, but it cannot by itself prove successful exploitation or credential theft.

Check the agent version on each managed node

CloudTrail is not an inventory of installed SSM Agent binaries. Use fleet inventory or host and package-management records to establish the version on each node, then compare it with AWS’s 3.3.4851.0 fix threshold and the applicable operating-system advisory. For Amazon Linux, verify the current package status against the Amazon Linux 2 or Amazon Linux 2023 advisory rather than relying only on a version seen in an old inventory record.

Question to answer Evidence to check
Was the node running an affected agent version? Per-node fleet inventory, host records, or package-management records, compared with AWS’s stated affected scope and fix threshold.
Was remote-host port forwarding authorized or used? Permissions for ssm:StartSession and SSM documents, plus CloudTrail events and Session Manager history.
What request context was recorded? Event identity, target, time, Region, source, document, and available request or error details.
Can the session be examined further? Session history and any configured session logs, including their retention and location.
How complete is the retrospective search? Account and Region coverage, date range, trail configuration, and retained records.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Know the limits of the available history

CloudTrail Event history shows the last 90 days of recorded management events in a Region and does not include data events. For an investigation extending beyond that window, use retained CloudTrail trail files in S3 or a CloudTrail Lake event data store if one was configured. The available evidence depends on the logging and retention settings in place.

Do not treat the absence of a matching event in a limited Event history search as proof that an account or node was unaffected. First account for missing Regions or accounts, the date range, trail configuration and retention, Session Manager history, and the node’s agent version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contain risk and preserve evidence

  • Upgrade affected installations to the latest available SSM Agent release. Use fleet inventory and the relevant platform advisory to verify that the update reached every managed node.
  • Until nodes are upgraded, restrict access to AWS-StartPortForwardingSessionToRemoteHost by scoping ssm:StartSession and SSM document permissions so untrusted principals cannot start those sessions.
  • If you find suspicious remote-host port-forwarding activity, assess whether the instance profile’s temporary credentials may have been exposed. Investigate related IAM activity and the resources those credentials could access; determine impact from your account-specific evidence.
  • Preserve relevant CloudTrail files, Session Manager history, configured session logs, and host evidence before their retention windows expire.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.