SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85656

HIGH · CVSS 7.8 EPSS 1.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A command injection vulnerability in the log4j-cve-2021-44228-hotpatch package on Amazon Linux versions prior to 1.3-9 allows local users to execute arbitrary commands with root privileges through specially crafted Java processes. This high-severity flaw poses a significant risk to system integrity and should be prioritized by organizations using affected versions of Amazon Linux and Java, particularly those with elevated user access. Immediate remediation is recommended to mitigate potential exploitation.

CVE
CVE-2026-85656
Severity
HIGH
CVSS
7.8
EPSS
1.12%
Linux Java

Original NVD Description

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.