Back to vendor advisories
AWS Security BulletinsCVE-2026-107783

CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell

Severity not listed 1 CVE Published Oct 9, 2026 at 3:56 PM UTC

Summary

Bulletin ID: 2026-132-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/09/2026 08:30 AM PDT

Description:

AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.

Impacted versions: <= v5.0.305

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by AWS

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.