PatchSiren cyber security CVE debrief
CVE-2026-107332 aws CVE debrief
CVE-2026-107332 debrief based on CVE Program and NVD records. The vulnerability involves insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0, allowing local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. Defenders and administrators using AWS Toolkit for VS Code should assess exposure and upgrade to version 4.10.0 or later. The CVE record and NVD entry provide details on this issue, emphasizing the need for upgraded permissions and secure token handling.
- Vendor
- aws
- Product
- aws-toolkit-vscode
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and administrators using AWS Toolkit for VS Code should assess exposure and upgrade to version 4.10.0 or later. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure secure configurations and mitigate potential unauthorized access to CodeCatalyst bearer tokens.
Why it matters
CVE-2026-107332 requires defenders to assess exposure and upgrade AWS Toolkit for VS Code to version 4.10.0 or later to prevent local users from obtaining CodeCatalyst bearer tokens
- Local users may obtain CodeCatalyst bearer tokens
- Insecure file permissions require verification and adjustment
- Upgrade to version 4.10.0 or later to mitigate
Technical summary
Insecure file permissions in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. This issue requires defenders to assess exposure and upgrade to version 4.10.0 or later to prevent unauthorized access to CodeCatalyst bearer tokens. The vulnerability highlights the need for secure file permissions and token handling in AWS Toolkit for VS Code deployments. Affected users should review and adjust file permissions, and monitor for potential unauthorized access.
Defensive priority
Upgrade to version 4.10.0 or later
Recommended defensive actions
- Upgrade to version 4.10.0 or later
- Review and adjust file permissions for token cache files
- Monitor for local user access to CodeCatalyst bearer tokens
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on insecure file permissions in AWS Toolkit for VS Code before 4.10.0, allowing local users to obtain CodeCatalyst bearer tokens. Evidence is based on CVE Program and NVD records, with details on affected versions and potential impact. Further verification is recommended to assess exposure and ensure secure configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107332 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107332
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107332 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107332
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio Code
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107332.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/aws/aws-toolkit-vscode/releases/tag/toolkit/v4.10.0
Supplemental source - patch, release-notes
-
Source reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-129-aws/
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.