AWS Tools for PowerShell CVE-2026-107783 (CVSS 4.0 6.7): an IAM user's cleartext AWS console password can land in PowerShell output and logs when sensitive cmdlets run with -WhatIf or -Confirm; fixed in 5.0.306, rotate any password that may have been logged
AWS published security bulletin 2026-132-AWS on 9 October 2026 (rated Important) for AWS Tools for PowerShell V5, the module administrators use to manage AWS services from PowerShell. In versions up to and including 5.0.305, under certain conditions an IAM user's plaintext AWS Management Console password is written to local host output without redaction, so it can end up in command output, PowerShell transcripts, command history and any log store that collects them. Anyone who can read those logs could then sign in to the console as that IAM user. AWS's GitHub advisory GHSA-q3x5-q6rm-c7p3 names the trigger: running cmdlets that carry sensitive arguments with the -WhatIf or -Confirm switches. The issue is fixed in 5.0.306. AWS's CVE record scores it 6.7 (CVSS 4.0, local attack, low privileges, user interaction) and asks users, after upgrading, to review PowerShell transcripts and log stores for passwords already disclosed and rotate any affected IAM console passwords. No exploitation reported. Primary: AWS security bulletin; vendor: GitHub advisory and 5.0.306 release.
- Product
- AWS Tools for PowerShell V5 (AWS.Tools modules)
- Versions
- 5.0.305 and earlier
- CVSS
- (CVSS 4.0, AWS as CNA)
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Update AWS Tools for PowerShell to 5.0.306 or later (Update-AWSToolsModule or your package source). Until then, do not use -WhatIf or -Confirm on cmdlets that take passwords or other secrets. Search PowerShell transcripts, history files, SIEM and CI logs for exposed console passwords, rotate any IAM console password that may have been logged, and prefer IAM Identity Center or federated sign-in with MFA over IAM user console passwords.
Primary: AWS security bulletin 2026-132-AWS — CVE-2026-107783, sensitive information in log file in AWS Tools for PowerShell (9 Oct 2026) · Vendor: AWS Tools for PowerShell GHSA-q3x5-q6rm-c7p3 — plaintext console password in host output (9 Oct 2026) · CVE: CVE-2026-107783 · AWS Tools for PowerShell 5.0.306 release
