CVE-2026-7791General

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-04); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-07: 1Mentions · 2026-06-26: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-06-26: 105-0405-0505-0706-26
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-051
General1
2026-05-071
Disclosure1
2026-06-261
General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7791 Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local n… https://www.cve.org/CVERecord?id=CVE-2026-7791

    Post summary

    The text cites CVE-2026-7791, describing an improper privilege management flaw in Amazon WorkSpaces' log rotation mechanism, but provides no PoC, exploit, active use, or patch information.

    00010217
    57.4K followersView on X
  • IntegSec@integ_sec
    General

    🚨 Cyber Spotlight: CVE-2026-7791 – What Businesses Need to Know A new security concern highlights the importance of staying updated and understanding vulnerabilities before they become bigger risks. In this video, we discuss CVE-2026-7791, a local privilege escalation vulnerability affecting the Amazon WorkSpaces Skylight Agent—what it means, the potential impact on businesses, and how organizations can respond. 🔐 Learn how proactive vulnerability management and timely security actions help protect your environment. 🎥 Watch the latest Cyber Spotlight episode and stay informed about today’s cybersecurity threats. 🌐 Visit our website for more cybersecurity insights, resources, and updates. ➡️ Follow us on linkedin: https://hubs.li/Q04mFbFL0 #CyberSpotlight #CVE20267791 #Cybersecurity #AWS #VulnerabilityManagement #InfoSec #CyberAwareness #SecurityUpdates #LearnCybersecurity

    Post summary

    The post promotes a video discussing CVE‑2026‑7791, a local privilege escalation flaw in Amazon WorkSpaces Skylight Agent, focusing on its impact and defensive actions without mentioning patches, exploits, or active attacks.

    0000052
    31 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent http://dlvr.it/TSQqTb #patchmanagement

    Post summary

    The text announces CVE-2026-7791, a local privilege escalation vulnerability in Amazon WorkSpaces Skylight Agent, detailing the exploit method.

    0000047
    2.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7791 Local Privilege Escalation in Amazon WorkSpaces Skylight W... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7791 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a newly disclosed CVE-2026-7791, citing a local privilege escalation in Amazon WorkSpaces Skylight, and provides a link for more details, but offers no exploit code, patch info, or claims of active exploitation.

    0000043
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7791 Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local n… https://www.cve.org/CVERecord?id=CVE-2026-7791 ----- Traducción: CVE-2026-7791 Ges… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑7791, detailing an improper privilege management flaw in Amazon WorkSpaces log rotation, and links to the official CVE record.

    0000033
    75 followersView on X

Explore more