CVE-2026-85656
published 2026-09-04CVE-2026-85656: An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands…
PriorityP352high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.12%
64.2th percentile
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amazon | log4j-cve-2021-44228-hotpatch | < 1.3-9.amzn2 | 1.3-9.amzn2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process w
ghsa_unreviewed·2026-09-04
CVE-2026-85656 [HIGH] CWE-78 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process w
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
VulDB
Amazon log4j-cve-2021-44228-hotpatch up to 1.3-9.amzn1 os command injection
vuldb·2026-09-04·CVSS 7.8
CVE-2026-85656 [HIGH] Amazon log4j-cve-2021-44228-hotpatch up to 1.3-9.amzn1 os command injection
A vulnerability categorized as very critical has been discovered in Amazon log4j-cve-2021-44228-hotpatch up to 1.3-9.amzn1. Affected is an unknown function. Such manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-85656. An attack has to be approached locally. There is no exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-04
Published