
Key points
- CVE-2026-107322 allows unauthenticated remote code execution
- The flaw stems from an incomplete list of disallowed inputs
- Version 1.7.1 of the databases-on-aws plugin resolves the issue
Amazon Web Services (AWS) has issued a security bulletin addressing a high-severity operating system command injection vulnerability in its databases-on-aws plugin. The flaw, tracked as CVE-2026-107322, affects versions prior to 1.7.1 and permits unauthenticated remote actors to execute arbitrary commands on the host system.
The National Vulnerability Database (NVD) assigns the vulnerability a CVSS score of 8.5, classifying it as high severity. The issue arises because the plugin maintains an incomplete list of disallowed inputs. An attacker can exploit this weakness by introducing a crafted database command value within the agent context, thereby bypassing input validation controls and achieving remote code execution on the machine running the helper service.
Technical Context
According to the NVD record, the underlying weakness is categorised as CWE-184, indicating a permissive list of allowed inputs rather than a restrictive blocklist. This architectural choice creates a gap where malicious payloads can slip through if they are not explicitly defined as forbidden. The vulnerability was identified in the Amazon Agent Plugins for AWS, specifically within the databases-on-aws component, which facilitates interactions between AWS agents and database services.
Impact on Organisations
Organisations using the databases-on-aws plugin before version 1.7.1 are exposed to significant risk. Because the attack requires no authentication, any external actor who can reach the agent context can potentially compromise the host. Successful exploitation grants the attacker arbitrary operating system command execution, which could lead to data theft, service disruption, or lateral movement within the network. The impact is confined to environments where the vulnerable plugin version is active and accessible.
What happens next
AWS advises users to upgrade to the databases-on-aws plugin version 1.7.1 or later immediately. After upgrading, administrators must verify that the updated plugin is active in each environment where it is deployed. No temporary workarounds have been confirmed in the available material; migration to the patched version is the sole remediation step provided by the vendor.
What to do and how to stay safe: AWS
- Automated tools find known code defects but miss logical errors in how systems interact.
- False positives waste time if you do not verify findings against your actual environment.
- Outsourcing the scan is affordable, but you must retain control of the remediation process.
Automated scanning finds known flaws but misses logic errors and configuration mistakes. Combine weekly scans with manual reviews and periodic penetration tests for a complete defence.
Step-by-step guide: Vulnerability Scanning for Small Teams: Practical Steps and Limits
General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-107322?
The NVD rates the severity as 8.5, which is classified as high.
Which versions of the databases-on-aws plugin are affected?
All versions prior to 1.7.1 are vulnerable to this OS command injection flaw.
How can an attacker exploit this vulnerability?
An unauthenticated remote actor can execute commands by sending a crafted database command value in the agent context.



