A
今日中
AWS Systems Manager Agent (SSM Agent) に深刻なSSRFの脆弱性(CVE-2026-89049)
📌 一言でいうと
AWS Systems Manager Agent (SSM Agent) に深刻なSSRFの脆弱性(CVE-2026-89049)が発見されました。ポート転送機能の検証不備により、攻撃者がリンクローカルエンドポイントへアクセスし、IAMロールの一時的な認証情報を取得する可能性があります。AWSは2026年7月13日にリリースされたバージョン 3.3.4851.0 でこの問題を修正済みです。
🔍該当判定
- AWS(Amazon Web Services)のクラウドサービスを利用している
- AWS上のサーバー(EC2など)で「AWS Systems Manager (SSM)」を利用して管理している
- サーバーにインストールされている「SSM Agent」のバージョンが 3.3.4851.0 より古い
上記いずれにも該当しない → 静観でOK
✅該当時の対応
SSM Agentを最新バージョン(3.3.4851.0以降)にアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】AWS SSM Agent CVE-2026-89049 対応について
お疲れさまです。AWS SSM Agentの深刻な脆弱性に関する情報共有です。
■ 概要
AWS Systems Manager Agentのポート転送機能にSSRFの脆弱性が判明しました。CVSS v3.1では9.9という極めて高いスコアが付けられており、悪用されると管理対象インスタンスのIAMロール認証情報が窃取される恐れがあります。
■ 影響範囲
- 対象製品: AWS Systems Manager Agent (SSM Agent)
- 修正済みバージョン: 3.3.4851.0 以降
■ 対応手順
1. 管理対象インスタンスにインストールされているSSM Agentのバージョンを確認してください。
2. バージョンが 3.3.4851.0 未満である場合は、速やかに最新版へアップデートを適用してください。
■ 参考情報
- AWS Security Advisory: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
対応優先度: 高
対応期限: 速やかに
お疲れさまです。AWS SSM Agentの深刻な脆弱性に関する情報共有です。
■ 概要
AWS Systems Manager Agentのポート転送機能にSSRFの脆弱性が判明しました。CVSS v3.1では9.9という極めて高いスコアが付けられており、悪用されると管理対象インスタンスのIAMロール認証情報が窃取される恐れがあります。
■ 影響範囲
- 対象製品: AWS Systems Manager Agent (SSM Agent)
- 修正済みバージョン: 3.3.4851.0 以降
■ 対応手順
1. 管理対象インスタンスにインストールされているSSM Agentのバージョンを確認してください。
2. バージョンが 3.3.4851.0 未満である場合は、速やかに最新版へアップデートを適用してください。
■ 参考情報
- AWS Security Advisory: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] AWS SSM Agent CVE-2026-89049 Remediation
Dear Team,
We are sharing critical information regarding a vulnerability in the AWS Systems Manager Agent (SSM Agent).
■ Overview
An SSRF vulnerability (CVE-2026-89049) has been identified in the port forwarding functionality of the SSM Agent. With a CVSS v3.1 score of 9.9, this flaw could allow an attacker to access link-local endpoints and steal temporary IAM role credentials from the managed instance.
■ Scope
- Affected Product: AWS Systems Manager Agent (SSM Agent)
- Fixed Version: 3.3.4851.0 and later
■ Remediation Steps
1. Verify the current version of the SSM Agent installed on your managed instances.
2. Update the agent to version 3.3.4851.0 or later immediately if you are running an older version.
■ Reference
- AWS Security Advisory: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Priority: High
Deadline: Immediate
Dear Team,
We are sharing critical information regarding a vulnerability in the AWS Systems Manager Agent (SSM Agent).
■ Overview
An SSRF vulnerability (CVE-2026-89049) has been identified in the port forwarding functionality of the SSM Agent. With a CVSS v3.1 score of 9.9, this flaw could allow an attacker to access link-local endpoints and steal temporary IAM role credentials from the managed instance.
■ Scope
- Affected Product: AWS Systems Manager Agent (SSM Agent)
- Fixed Version: 3.3.4851.0 and later
■ Remediation Steps
1. Verify the current version of the SSM Agent installed on your managed instances.
2. Update the agent to version 3.3.4851.0 or later immediately if you are running an older version.
■ Reference
- AWS Security Advisory: Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
Priority: High
Deadline: Immediate