CVE-2026-7461 - OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials
Bulletin ID: 2026-024-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/30 13:30 PM PDT Description: Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. The Amazon ECS agent supports mounting FSx for Windows File Server volumes in task definitions on Windows EC2 instances. We identified CVE-2026-7461, a command injection issue in FSx volume mounting that enables code execution with SYSTEM privileges via a specially crafted credentials in ECS task definitions. Impacted versions: Version 1.47.0 through 1.102.2 of the ECS Agent for Windows Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- There is a command injection issue in FSx volume mounting that enables code execution with SYSTEM privileges.
- Who is affected
- Deployments of ECS Agent for Windows versions 1.47.0 through 1.102.2.
- Urgency
- Remediation is important as it allows for remote code execution with high privileges.
- Action
- Update to a patched version of the ECS Agent.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ECS Agent
Get an email when a new ECS Agent advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-024-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-74610.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7461 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - OS Command
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-90935: Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed…nvd · 2026-09-14
- unknownCVE-2026-77051: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabi…nvd · 2026-09-14
- criticalCVE-2026-90898: Bifrost registers MCP clients through its management API. A stdio client is a command plus arg…nvd · 2026-09-14
- highCVE-2026-89180: EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing u…nvd · 2026-09-14
- unknownCVE-2026-82232: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerabi…nvd · 2026-09-14
- mediumCVE-2026-90698: A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affe…nvd · 2026-09-14
More from AWS Security Bulletins
- unknownCVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration2026-09-11
- unknownCVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v22026-09-11
- unknownCVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin2026-09-11
- unknownCVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection2026-09-11
- unknownCVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Syste…2026-09-10