Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-13769 – Insecure file permissions in AWS CLI

A security issue was found in the AWS Command Line Interface (CLI) on Unix-like systems. By default, it created credential and configuration files that could be read by all users on the same computer. This could let other local users see sensitive AWS credentials. AWS fixed this in updated AWS CLI versions and recommends users upgrade to these versions.

QCS published 10/10/2026, 7:43:23 am ISTVendor disclosure 9/10/2026, 11:49:17 pm ISTVerified 11/10/2026, 3:31:22 am ISTRevision 1

In plain language

What this advisory means

A security issue was found in the AWS Command Line Interface (CLI) on Unix-like systems. By default, it created credential and configuration files that could be read by all users on the same computer. This could let other local users see sensitive AWS credentials. AWS fixed this in updated AWS CLI versions and recommends users upgrade to these versions.

Technical explanation

How the issue affects the environment

CVE-2026-13769 is an insecure file permission vulnerability in AWS CLI on Unix-like systems. When the system's umask is left at default (which often permits files to be world-readable), AWS CLI wrote credential and configuration files with permissions that allow any local user to read them. This exposure risks unauthorized local access to AWS credentials stored by AWS CLI. The issue is addressed in AWS CLI v1 1.44.78 and v2 2.34.29, which enforce stricter file permissions when writing sensitive files.

Operational impact

Why teams should care

If exploited, this vulnerability could allow any local user on the same host to read AWS credentials belonging to other users, potentially leading to unauthorized access to AWS services and resources. This could result in data exposure, service disruption, or unauthorized charges. Organizations using AWS CLI on shared or multi-user Unix-like systems are at risk until they upgrade.

Immediate action

Upgrade AWS CLI to version v1 1.44.78 or AWS CLI v2 2.34.29 or later. Also ensure that any forked or derivative versions of AWS CLI incorporate these fixes. Verify file permissions on credential and configuration files to confirm they are not world-readable.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsAWS CLI v1 1.44.78, AWS CLI v2 2.34.29

Temporary risk reduction

The official bulletin does not specify any workaround. Users should upgrade to the fixed versions to address the issue.

Evidence and validation checklist

  • Official AWS Security Bulletin: https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/
  • CVE-2026-13769 entry referenced by AWS
  • Release notes for AWS CLI v1 1.44.78 and v2 2.34.29 indicating fix for file permission issue.
  • Statement that default umask allows world-readable credentials files on Unix-like systems
  • Recommendation from AWS to upgrade to fixed AWS CLI versions.

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source