216.73.216.226

CVE-2026-7791

· Published 04/05/2026 22:16 · Modified 04/05/2026 22:16

Labels: CVE-2026-7791 2026-05-04CVE-2026-7791CWE-367ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
04/05/2026 22:16
Modified
04/05/2026 22:16
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
amazon / workspaces cpe:2.3:a:amazon:workspaces:<2.6.2034.0:*:*:*:*:*:*:*

References