Vulnerability Intelligence Report
OS command injection in Amazon log4j-cve-2021-44228-hotpatch
CVE-2026-85656
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Injection
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Amazon | log4j-cve-2021-44228-hotpatch | 0 < 1.3-9.amzn2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Vulnerability Class
Injection
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Amazon · Vendor · USA |
| Reserved | 2026-09-04T13:13:08 |
| Published | 2026-09-04T17:33:20 |
| Last Updated | 2026-09-04T17:49:26 |
Community Chatter & Buzz