PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104019 AWS CVE debrief

A critical vulnerability exists in Amazon SageMaker Distribution, which could allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials. This issue affects multiple versions of SageMaker Distribution and can be remediated by upgrading to specific patched versions.

Vendor
AWS
Product
sagemaker-distribution
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-09
Advisory published
2026-10-02
Advisory updated
2026-10-09

Who should care

Defenders responsible for Amazon SageMaker Distribution and Unified Studio deployments should assess exposure and prioritize remediation. Specifically, those with project contributor permissions or managing Studio Spaces should verify their versions and upgrade as necessary.

Why it matters

This critical vulnerability in Amazon SageMaker Distribution requires immediate attention from defenders. An authenticated remote user with project contributor permissions could exploit this issue to execute arbitrary commands in another project member's Studio Space and obtain their temporary execution role credentials. Defenders should assess exposure, prioritize remediation, and verify that Studio Spaces adopt the latest patch of their minor line on restart.

  • Potential lateral movement within Studio Spaces
  • Elevation of privileges for authenticated remote users
  • Exposure of temporary execution role credentials
  • Possible disruption of Studio Space operations

Technical summary

The vulnerability exists in the Studio Space startup validation script in Amazon SageMaker Distribution. An authenticated remote user with project contributor permissions could execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property. This issue affects multiple versions of SageMaker Distribution, including 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in

Defensive priority

High

Recommended defensive actions

  • Upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use.
  • Users on minor lines that have reached end of support must move to a supported minor line.
  • Verify that Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and remediation steps. However, the corpus does not establish evidence of exploitation or specific business impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104019 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104019

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104019 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104019

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribut

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104019.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/aws/sagemaker-distribution/releases

    Supplemental source - release-notes, patch

  • Source reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-125-aws/

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/aws/sagemaker-distribution/security/advisories/GHSA-w64x-664p-7w66

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.