CVE-2026-7461 Details
Description
Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a specially crafted username field in an ECS task definition. This issue requires permissions to register ECS task definitions or write to the Secrets Manager or SSM Parameter Store credentials used by the FSx volume configuration. To remediate this issue, users should upgrade to version 1.103.0.
A command injection vulnerability has been identified in the Amazon ECS Agent on Windows, affecting versions 1.47.0 through 1.102.2. This vulnerability arises from improper handling of inputs in the FSx Windows File Server volume mounting component. A remote authenticated attacker could exploit this issue to execute shell commands with SYSTEM privileges on the underlying host. The exploitation involves crafting a specific username field in an ECS task definition. This vulnerability requires permissions to register ECS task definitions or to write to the Secrets Manager or SSM Parameter Store credentials used in the FSx volume configuration.
Users should upgrade to Amazon ECS Agent version 1.103.0. Instructions for upgrading to the latest Amazon ECS-optimized Windows AMI are available in the Amazon ECS documentation. For those unable to update, it is recommended to restrict ecs:RegisterTaskDefinition permissions to trusted IAM principals and limit write access to Secrets Manager secrets referenced in FSx volume configurations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-024-aws/ | AMZN | Vendor Advisory |
| https://github.com/aws/amazon-ecs-agent/releases/tag/v1.103.0 | AMZN | Release Notes |
| https://github.com/aws/amazon-ecs-agent/security/advisories/GHSA-fc67-c4hg-q653 | AMZN | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon amazon ecs container agent | >= 1.47.0, < 1.103.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | CVE Modified | AMZN |
| Apr 30, 2026 | New CVE Received | AMZN |