Ghostwire

CVE-2026-7791: Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon...

HIGH CVSS 7.5

Published: May 4, 2026 | Last Modified: May 4, 2026

Description

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References