2026-125-AWSHigh

CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution

Published
October 2, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a network validation against all the available SageMaker connections in a project. Under certain conditions, improper sanitization of connection details during this validation could allow arbitrary code to be executed in the Space of another project member. In projects with the Trusted Identity Propagation feature enabled, this issue could result in a user with project contributor permissions (or higher) gaining access to another member's temporary execution role credentials and calling downstream trusted identity propagation-enabled AWS services on their behalf. We implemented a fix to all supported SageMaker Distribution versions to sanitize connection details during the startup validation process. The fix is deployed globally and will apply to all Spaces automatically on the next startup. Impacted versions:

  • 2.8.x - 2.13.x: all versions affected, no fix (end of support)
  • 2.14.x:
  • 3.3.x - 3.8.x: all versions affected, no fix (end of support)
  • 3.9.x:
  • 4.0.x:
  • 4.1.x:
  • 4.2.x:
  • 4.3.x:
  • 4.4.x:
  • 4.5.x: not affected

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)