In plain language
What this advisory means
A security flaw was found in the Amazon Agent Plugins for AWS, specifically in the databases-on-aws plugin versions before 1.7.1. This flaw could allow an unauthorized remote attacker to execute commands on the operating system of the host machine if the agent processes crafted input that then triggers execution in a local helper script. The issue only arises if the agent runs the helper with the malicious input. Amazon has fixed this in version 1.7.1, and users should upgrade to that version or later. If upgrading isn't immediately possible, Amazon recommends avoiding certain plugin features and running the processes with minimal permissions to reduce risk.
Technical explanation
How the issue affects the environment
The vulnerability identified as CVE-2026-107322 involves OS command injection in the databases-on-aws plugin of Amazon Agent Plugins. The root cause is an incomplete input validation where disallowed inputs are insufficiently filtered in versions prior to 1.7.1. A remote unauthenticated actor can supply specially crafted database commands which, if subsequently passed to the local helper script by the agent, result in command execution on the host operating system under the permissions of the helper process. The vulnerable component is not a network listener, so exploitation requires that the agent invoke the vulnerable helper with malicious input. Importantly, this flaw does not affect the Aurora DSQL service nor does it bypass database privilege controls. The fixed code is available starting in databases-on-aws version 1.7.1 and a specific Git commit revision is noted for repository users.
Operational impact
Why teams should care
If exploited, attackers could execute arbitrary operating system commands on the host machine where the helper script runs. Since such commands run with the same permissions as the helper process, this could lead to unauthorized changes or access at the OS level, potentially compromising system integrity or data confidentiality within affected environments. However, the Vulnerability does not allow attackers to bypass database privileges or directly compromise the Aurora DSQL database service. Organizations using the plugin should upgrade to avoid risk and apply mitigations to reduce potential impact.
Immediate action
Upgrade to databases-on-aws version 1.7.1 or later where the fix is included. For repository users, ensure usage of commit 8b13a503746a4ebb0402b936645163224058bde3 or later instead of relying solely on the 1.7.1 release tag. Verify the updated plugin is active in all environments and that any forks or derivatives include the fix. Rotate or revoke AWS credentials accessible to the helper host if compromise is suspected, and review and restrict database roles and IAM-to-database role mappings accordingly.
Affected and fixed releases
Temporary risk reduction
If immediate upgrade is not possible, avoid using the optional psql connection helper command path that invokes the vulnerable helper script. Instead, use only manually reviewed SQL commands or the DSQL MCP server provided through the plugin. Run the agent and helper processes as unprivileged OS users with dedicated, minimally scoped AWS IAM roles and database roles (preferably read-only). Avoid granting administrative database roles for routine operations to limit possible damage.
Evidence and validation checklist
- Amazon’s official AWS Security Bulletin describing CVE-2026-107322
- Details specifying incomplete disallowed input filtering in databases-on-aws plugin before version 1.7.1
- Public fix released in databases-on-aws version 1.7.1 dated August 26, 2026
- Recommendations to upgrade, use minimal privileges, and avoid helper command path as a workaround
- Acknowledgement credit to security researcher Shay Sakazi
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
