← Back to CVE List
Vulnerability Intelligence Report
OS command injection in Amazon log4j-cve-2021-44228-hotpatch

CVE-2026-85656

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.

Injection No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Affected Products & Versions

Vendor Product Affected Versions
Amazon log4j-cve-2021-44228-hotpatch 0 < 1.3-9.amzn2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Injection

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAmazon · Vendor · USA
Reserved2026-09-04T13:13:08
Published2026-09-04T17:33:20
Last Updated2026-09-04T17:49:26

LINK COPIED TO CLIPBOARD