Disclosure summary
An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context. To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.
Source-reported weakness categories
CWE-184
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107322
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Latest Bulletins · RSS-7b2fbfb42940026aec6b1809320a57b144e
Open original source · Updated Oct 08, 2026
CVE-2026-107322 - OS command injection in Amazon Agent Plugins for AWS databases-on-aws
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2026-10-08T15:16:59-04:00
MODIFIED 2026-10-08T16:17:31-04:00
INGESTED 2026-10-10T20:55:03-04:00