CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell
Bulletin ID: 2026-132-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/09/2026 08:30 AM PDT
Description:
AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.
Impacted versions: <= v5.0.305
Resolution:
This issue has been addressed in 5.0.306 version. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
Avoid using -WhatIf / -Confirm with cmdlets that contain sensitive information in its arguments when using AWS Tools for PowerShell in versions <= 5.0.305.
References:
Please email aws-security@amazon.com with any security questions or concerns.