AWS SSM Agent flaw lets authenticated attackers bypass port-forwarding restrictions and access sensitive services, including EC2 metadata.