CVE-2026-7791: Amazon Workspaces

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.

Affected products

Published 2026-05-04. Last modified 2026-06-17.