Disclosure summary
Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. To remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.
Source-reported weakness categories
CWE-532
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107783
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Latest Bulletins · RSS-091786eb1e65d4e34513d3b347d72078529
Open original source · Updated Oct 09, 2026
CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2026-10-09T12:17:24-04:00
MODIFIED 2026-10-09T14:17:02-04:00
INGESTED 2026-10-10T20:55:12-04:00