Junglewise Threat Intelligence

CVE-2026-7791: Amazon WorkSpaces Skylight Agent privilege escalation via TOCTOU race condition

CVE-2026-7791 · Severity: high · Published 2026-05-04

Technologies: Amazon AWS. Vendors: Amazon.

Executive brief

A vulnerability in the Amazon WorkSpaces Skylight Agent could allow a standard user to gain full administrative control over their virtual desktop environment. This agent is a background service responsible for managing system configurations and health monitoring on Windows-based WorkSpaces. An attacker with existing access to a WorkSpace could exploit this flaw to bypass security restrictions, potentially leading to unauthorized software installation or data access.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the Amazon Skylight Workspace Config Service (slwsconfigservice) during the log file archival process. By exploiting this race condition, a local authenticated user without administrative rights can manipulate file operations to gain SYSTEM-level privileges. The vulnerability specifically impacts Windows WorkSpaces where the 'Local Administrator Setting' is not enabled. The issue is resolved in version 2.6.2034.0, and users can apply the fix by rebooting their impacted WorkSpaces to trigger an update.

Affected products

  • Amazon WorkSpaces Skylight Workspace Config Service (slwsconfigservice) < 2.6.2034.0

Timeline

  • 2026-05-04: disclosed
  • 2026-05-04: patched: Fixed in version 2.6.2034.0

References

Related threats