CVE-2026-107783 PUBLISHED

Insertion of sensitive information into log file in AWS Tools for PowerShell

Assigner: AMZN
Reserved: 08.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.

To remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor AWS
Product aws-tools-for-powershell
Versions Default: unaffected
  • affected from 0 to 5.0.305 (incl.)

References

Problem Types

  • CWE-532 Insertion of sensitive information into log file CWE

Impacts

  • CAPEC-150 Collect Data from Common Resource Locations