To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used. | |
| Title | OS command injection in Amazon Agent Plugins for AWS databases-on-aws | |
| First Time appeared |
Aws
Aws databases-on-aws |
|
| Weaknesses | CWE-184 | |
| CPEs | cpe:2.3:a:aws:databases-on-aws:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws databases-on-aws |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-10-08T19:19:24.257Z
Reserved: 2026-10-07T17:36:30.283Z
Link: CVE-2026-107322
No data.
Status : Awaiting Analysis
Published: 2026-10-08T19:16:59.857
Modified: 2026-10-08T20:17:31.590
Link: CVE-2026-107322
No data.
OpenCVE Enrichment
No data.
-
CWE-184
Incomplete List of Disallowed Inputs