CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-13769

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-07-01
Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register). To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later.

CSIRTS triage

What
The AWS CLI has insecure file permissions that allow local users to read credentials.
Who is affected
Unix-like system deployments of AWS CLI versions 1.44.77 and 2.34.28 or earlier.
Urgency
Remediation is important due to potential exposure of sensitive credentials.
Action
Configure umask to restrict file permissions or upgrade to a secure version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-13769

Get an email if CVE-2026-13769 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-13769

CVE.org record

Embed the live status

CVE-2026-13769 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-13769 status](https://www.csirts.com/badge/CVE-2026-13769)](https://www.csirts.com/cve/CVE-2026-13769)