Skip to main content

CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell

Bulletin ID: 2026-132-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/09/2026 08:30 AM PDT

Description:

AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.

Impacted versions: <= v5.0.305

Resolution:

This issue has been addressed in 5.0.306 version. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Avoid using -WhatIf / -Confirm with cmdlets that contain sensitive information in its arguments when using AWS Tools for PowerShell in versions <= 5.0.305.

References:


Please email aws-security@amazon.com with any security questions or concerns.