CVE-2026-104019: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in AWS sagemaker-distribution
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.
AI Analysis
Technical Summary
This vulnerability involves improper neutralization of special elements used in OS commands (CWE-78) within the startup script of SageMaker Spaces in AWS SageMaker Unified Studio. The startup script validates network connections but fails to properly sanitize connection details, enabling an attacker with project contributor or higher permissions to execute arbitrary code in another member's Space. When Trusted Identity Propagation is enabled, this can escalate privileges by exposing temporary execution role credentials, allowing unauthorized calls to trusted AWS services. AWS has released patches for multiple sagemaker-distribution version branches, and the fix is automatically applied on the next startup for supported versions.
Potential Impact
Successful exploitation can lead to arbitrary code execution within another project member's SageMaker Space, potentially resulting in unauthorized access to temporary execution role credentials. This enables attackers to invoke downstream AWS services with elevated privileges, compromising confidentiality, integrity, and availability of resources. The vulnerability has a CVSS 3.1 score of 9.0 (critical), indicating high severity with network attack vector, low attack complexity, and requiring privileges but allowing significant impact.
Mitigation Recommendations
AWS has implemented an official fix that sanitizes connection details during the startup validation process. This fix is deployed globally and automatically applies to all supported SageMaker Spaces on their next startup. Users should upgrade to the fixed versions: 2.14.12 or later for the 2.14.x branch, 3.9.12 or later for the 3.9.x branch, 4.0.11 or later for 4.0.x, 4.1.11 or later for 4.1.x, 4.2.8 or later for 4.2.x, 4.3.5 or later for 4.3.x, and 4.4.3 or later for 4.4.x. Versions 2.8.x, 2.13.x, 3.3.x, and 3.8.x are end-of-support and remain unpatched. No additional mitigation is required beyond applying these updates.
CVE-2026-104019: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in AWS sagemaker-distribution
Description
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.
CVSS v3.1
Score 9.0critical
Affected software
AWS
sagemaker-distribution
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper neutralization of special elements used in OS commands (CWE-78) within the startup script of SageMaker Spaces in AWS SageMaker Unified Studio. The startup script validates network connections but fails to properly sanitize connection details, enabling an attacker with project contributor or higher permissions to execute arbitrary code in another member's Space. When Trusted Identity Propagation is enabled, this can escalate privileges by exposing temporary execution role credentials, allowing unauthorized calls to trusted AWS services. AWS has released patches for multiple sagemaker-distribution version branches, and the fix is automatically applied on the next startup for supported versions.
Potential Impact
Successful exploitation can lead to arbitrary code execution within another project member's SageMaker Space, potentially resulting in unauthorized access to temporary execution role credentials. This enables attackers to invoke downstream AWS services with elevated privileges, compromising confidentiality, integrity, and availability of resources. The vulnerability has a CVSS 3.1 score of 9.0 (critical), indicating high severity with network attack vector, low attack complexity, and requiring privileges but allowing significant impact.
Mitigation Recommendations
AWS has implemented an official fix that sanitizes connection details during the startup validation process. This fix is deployed globally and automatically applies to all supported SageMaker Spaces on their next startup. Users should upgrade to the fixed versions: 2.14.12 or later for the 2.14.x branch, 3.9.12 or later for the 3.9.x branch, 4.0.11 or later for 4.0.x, 4.1.11 or later for 4.1.x, 4.2.8 or later for 4.2.x, 4.3.5 or later for 4.3.x, and 4.4.3 or later for 4.4.x. Versions 2.8.x, 2.13.x, 3.3.x, and 3.8.x are end-of-support and remain unpatched. No additional mitigation is required beyond applying these updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- AMZN
- Date Reserved
- 2026-10-01T16:57:39.545Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://aws.amazon.com/security/security-bulletins/2026-125-aws/","vendor":"AWS"}]
Threat ID: 6ac01129a43b0b3b89fe436d
Added to database: 10/02/2026, 20:16:41 UTC
Last enriched: 10/02/2026, 20:29:56 UTC
Last updated: 10/02/2026, 20:55:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.