Amazon Ecs Container AgentApplication · Amazon

CVE-2026-7461

HIGH · 7.2 CVSS v3.1 Published 2026-04-30
Fix available
A fix is available. Upgrade to 1.103.0 or later.
See remediation →
78/100
Remediation priority · High
Remotely reachable Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a specially crafted username field in an ECS task definition. This issue requires permissions to register ECS task definitions or write to the Secrets Manager or SSM Parameter Store credentials used by the FSx volume configuration. To remediate this issue, users should upgrade to version 1.103.0.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

Improper input validation in the FSx Windows File Server volume mounting component of Amazon ECS Agent on Windows allows an authenticated attacker with task definition registration or Secrets Manager/SSM Parameter Store write permissions to inject OS commands via a specially crafted username field, achieving SYSTEM-level code execution on the underlying host.

MitigationUpgrade Amazon ECS Agent on Windows to version 1.103.0 or later to receive the patch for this command injection vulnerability.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Amazon Ecs Container AgentApplication
Affected:>= 1.47.0, < 1.103.0

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check ECS Agent version on Windows hosts
    Retrieve the running version of Amazon ECS Agent (e.g., via agent introspection API, Docker inspect, or EC2 instance metadata). Compare the installed version against the affected range: versions >= 1.47.0 and < 1.103.0.
    Affected if The ECS Agent version falls within 1.47.0 to 1.102.x inclusive on Windows.
  2. Identify FSx Windows File Server volume configurations
    Review ECS task definitions and running tasks for any volume configurations that reference FSx Windows File Server (look for volume type "fsx.windows" or FSx-related volume mount configurations).
    Affected if Task definitions include FSx Windows File Server volume mounts.
  3. Inspect volume mount username fields
    Examine the username field within FSx volume mount configurations in task definitions. Look for any username values that may contain special characters or patterns indicative of command injection attempts.
    Affected if A username field in an FSx volume configuration contains unexpected characters that could represent injected commands.
  4. Verify task definition registration permissions
    Determine whether IAM principals have permissions to register or modify task definitions (ecs:RegisterTaskDefinition) or to write to Secrets Manager or SSM Parameter Store (secretsmanager:PutSecretValue, ssm:PutParameter).
    Affected if Untrusted principals have task definition registration or secrets/write permissions, allowing them to introduce malicious username fields.

A Windows host is affected if it runs Amazon ECS Agent version 1.47.0 through 1.102.x AND uses FSx Windows File Server volume mounts where an attacker could control the username field via task definition registration or secrets/SSM permissions.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 1.103.0 or later
Fixed in 1.103.0
Interim mitigation

Upgrade Amazon ECS Agent on Windows to version 1.103.0 or later to receive the patch for this command injection vulnerability.

Recommended fix High confidence

Amazon ECS Container Agent version 1.103.0

  1. Identify Windows EC2 instances running Amazon ECS Container Agent versions between 1.47.0 and 1.102.x using AWS Systems Manager Session Manager, AWS CLI, or Amazon ECS console
  2. Stop any running ECS tasks on the affected container instances to ensure a safe upgrade
  3. Upgrade the Amazon ECS Container Agent on Windows to version 1.103.0 or later. For EC2 instances, this is typically done by restarting the ECS service or the instance itself, which triggers the latest agent bootstrap. For custom AMIs, rebuild the AMI with agent version 1.103.0 or use EC2 Auto Scaling group rolling updates
  4. Verify the upgrade was successful by checking the ECS container agent version on the instances using the ECS container introspection endpoint or by querying the ECS DescribeContainerInstances API
  5. Ensure no regression in existing ECS tasks and that FSx volume mounts function correctly after the upgrade

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Amazon Ecs Container Agent Scoped from the published advisory
  • Consultation3.0 h
  • Implementation8.0 h
  • Testing5.0 h
  • Review / QA2.0 h
18.0 hours of engineering $3,150
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,040.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-7461 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-7461 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data