PatchSiren cyber security CVE debrief
CVE-2026-104019 AWS CVE debrief
A critical vulnerability exists in Amazon SageMaker Distribution, which could allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials. This issue affects multiple versions of SageMaker Distribution and can be remediated by upgrading to specific patched versions.
- Vendor
- AWS
- Product
- sagemaker-distribution
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-02
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-02
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Amazon SageMaker Distribution and Unified Studio deployments should assess exposure and prioritize remediation. Specifically, those with project contributor permissions or managing Studio Spaces should verify their versions and upgrade as necessary.
Why it matters
This critical vulnerability in Amazon SageMaker Distribution requires immediate attention from defenders. An authenticated remote user with project contributor permissions could exploit this issue to execute arbitrary commands in another project member's Studio Space and obtain their temporary execution role credentials. Defenders should assess exposure, prioritize remediation, and verify that Studio Spaces adopt the latest patch of their minor line on restart.
- Potential lateral movement within Studio Spaces
- Elevation of privileges for authenticated remote users
- Exposure of temporary execution role credentials
- Possible disruption of Studio Space operations
Technical summary
The vulnerability exists in the Studio Space startup validation script in Amazon SageMaker Distribution. An authenticated remote user with project contributor permissions could execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property. This issue affects multiple versions of SageMaker Distribution, including 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in
Defensive priority
High
Recommended defensive actions
- Upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use.
- Users on minor lines that have reached end of support must move to a supported minor line.
- Verify that Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and remediation steps. However, the corpus does not establish evidence of exploitation or specific business impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104019 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104019
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104019 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104019
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribut
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104019.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/aws/sagemaker-distribution/releases
Supplemental source - release-notes, patch
-
Source reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-125-aws/
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/aws/sagemaker-distribution/security/advisories/GHSA-w64x-664p-7w66
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.