Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 05 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Log Rotation in Amazon WorkSpaces |
Mon, 04 May 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon workspaces |
|
| Vendors & Products |
Amazon
Amazon workspaces |
Mon, 04 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM. | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-05-06T03:56:05.603Z
Reserved: 2026-05-04T18:48:58.397Z
Link: CVE-2026-7791
Updated: 2026-05-05T13:22:49.932Z
Status : Awaiting Analysis
Published: 2026-05-04T22:16:20.697
Modified: 2026-05-05T19:32:23.613
Link: CVE-2026-7791
No data.
OpenCVE Enrichment
Updated: 2026-05-05T00:00:10Z