PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89332 Amazon CVE debrief

CVE-2026-89332 is a vulnerability in the Kiro Powers feature of Amazon Kiro IDE before version 0.8.135. The issue allows remote unauthenticated actors to potentially obtain sensitive information from a developer workstation by modifying workspace settings and redirecting registry requests to an attacker-controlled endpoint. This vulnerability has a medium severity and requires immediate attention from developers and administrators using Amazon Kiro IDE, especially those who have opened projects in versions prior to 0.8.135. The vulnerability can be remediated by upgrading to Kiro IDE version 0.8.135 or later and rotating credentials for projects opened in earlier versions.

Vendor
Amazon
Product
Kiro IDE
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Developers and administrators using Amazon Kiro IDE, especially those who have opened projects in versions prior to 0.8.135, should assess exposure and take remediation steps. This includes upgrading to Kiro IDE version 0.8.135 or later and rotating credentials for projects opened in earlier versions. Additionally, defenders should review workspace settings and registry requests for potential tampering and verify Kiro IDE version and upgrade to 0.8.135 or

Why it matters

CVE-2026-89332 is a medium-severity vulnerability in Amazon Kiro IDE that could allow remote unauthenticated actors to obtain sensitive information from developer workstations. Defenders should prioritize upgrading to version 0.8.135 or later and rotating credentials for projects opened in earlier versions.

  • Potential sensitive information disclosure from developer workstations
  • Possible unauthorized access to workspace data
  • Need to verify Kiro IDE version and upgrade to 0.8.135 or later
  • Requirement to rotate credentials for projects opened in earlier versions

Technical summary

The Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 is vulnerable to inclusion of functionality from an untrusted control sphere. Crafted repository content can cause the agent to modify the workspace settings file, redirecting the Kiro Powers registry request to an attacker-controlled endpoint and sending workspace data to that endpoint when the Powers panel is opened. This vulnerability can be exploited by remote unauthenticated actors, potentially allowing them to obtain sensitive information from developer workstations.

Defensive priority

Upgrade to Kiro IDE version 0.8.135 or later and rotate credentials for projects opened in earlier versions.

Recommended defensive actions

  • Upgrade to Kiro IDE version 0.8.135 or later
  • Rotate credentials for projects opened in earlier versions
  • Review workspace settings and registry requests for potential tampering
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is described in the CVE record and NVD entry. Amazon and Kiro provide references to security bulletins and changelogs. The CVE record was published on 2026-09-11T20:19:23.670Z and has not been modified since then. The NVD entry provides additional information on the vulnerability, including its CVSS score and severity. The vulnerability affects Amazon Kiro IDE versions prior to 0.8.135 and can be exploited by remote unauthenticated actors.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89332 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89332

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89332 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89332

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-111-aws/

    ff89ba41-3aa1-4d27-914a-91399e9639e5

  • Source reference

    Unverified legacy reference

    URL: https://kiro.dev/changelog/ide/0-8/

    ff89ba41-3aa1-4d27-914a-91399e9639e5

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.