AWS Latest Bulletins
Follow
CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution
Amazon SageMaker Unified Studio is an AWS service that integrates data, analytics, and AI development. It allows users to access and act on organizational data using purpose-built tools. A critical vulnerability, CVE-2026-104019, has been identified in the startup process of SageMaker Spaces within Unified Studio. This issue stems from improper sanitization of network connection details during a validation process. Under specific circumstances, this flaw could lead to arbitrary code execution within another project member's SageMaker Space. If the Trusted Identity Propagation feature is enabled, a contributor could potentially gain access to another member's temporary execution role credentials. This could then be used to call downstream AWS services on that member's behalf. AWS has implemented a fix to address this vulnerability by sanitizing connection details during the startup validation. The fix has been deployed globally and will automatically apply to all Spaces upon their next startup. Several versions are affected, including specific ranges of 2.x, 3.x, 4.0.x, 4.1.x, 4.2.x, and 4.3.x. Older versions (prior to 2.8.0 and 3.3.0) and versions 4.5.x are not affected.