SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85028

HIGH · CVSS 7.8 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The AWS FPGA Development Kit prior to version 2.3.4 contains a vulnerability that allows local users to exploit insecure permissions in a temporary file directory, potentially leading to arbitrary code execution with root privileges. This risk arises during the installation process, where crafted shell content can be placed in a world-writable directory. Organizations utilizing this toolkit should prioritize upgrading to the latest version to mitigate the risk of unauthorized access and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85028
Severity
HIGH
CVSS
7.8
EPSS
0.12%

Original NVD Description

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges. To remediate this issue, users should upgrade to version 2.3.4.