SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-87912

MEDIUM · CVSS 5.9 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The AWS Security Agent plugin in Amazon aws-agents-for-devsecops prior to version 1.1.0 is vulnerable due to a lack of S3 bucket ownership verification, potentially allowing remote attackers to access sensitive data, including credentials and infrastructure state, from a compromised workspace. Organizations using this plugin should prioritize upgrading to version 1.1.0 and ensure that their scan output buckets are owned by their own accounts to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87912
Severity
MEDIUM
CVSS
5.9
EPSS
0.25%

Original NVD Description

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered.