Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters. | |
| Title | OS command injection in Amazon log4j-cve-2021-44228-hotpatch | |
| First Time appeared |
Amazon
Amazon log4j-cve-2021-44228-hotpatch |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:amazon:log4j-cve-2021-44228-hotpatch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon log4j-cve-2021-44228-hotpatch |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-04T17:49:26.880Z
Reserved: 2026-09-04T13:13:08.811Z
Link: CVE-2026-85656
Updated: 2026-09-04T17:49:22.697Z
Status : Received
Published: 2026-09-04T18:18:06.133
Modified: 2026-09-04T18:18:06.133
Link: CVE-2026-85656
No data.
OpenCVE Enrichment
Updated: 2026-09-04T19:00:14Z