Vulnerability Description
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading to local privilege escalation to SYSTEM.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-7791?
CVE-2026-7791 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to p...
How severe is CVE-2026-7791?
CVE-2026-7791 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7791?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.