CVE-2026-104019
Received Received - Intake

OS Command Injection in Amazon SageMaker Distribution

Vulnerability report for CVE-2026-104019, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: AMZN

Description

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization. To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
amazon sagemaker_distribution From 2.8.0 (inc) to 4.5.0 (exc)
amazon sagemaker_distribution 4.5
amazon sagemaker_distribution 2.14.12
amazon sagemaker_distribution 3.9.12
amazon sagemaker_distribution 4.0.11
amazon sagemaker_distribution 4.1.11
amazon sagemaker_distribution 4.2.8
amazon sagemaker_distribution 4.3.5
amazon sagemaker_distribution 4.4.3
amazon sagemaker_distribution to 2.14.12 (exc)
amazon sagemaker_distribution to 3.9.12 (exc)
amazon sagemaker_distribution to 4.0.11 (exc)
amazon sagemaker_distribution to 4.1.11 (exc)
amazon sagemaker_distribution to 4.2.8 (exc)
amazon sagemaker_distribution to 4.3.5 (exc)
amazon sagemaker_distribution to 4.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an OS command injection vulnerability in Amazon SageMaker Distribution's Studio Space startup validation script. It allows an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space. The issue occurs when crafted connection resource properties are interpolated into a shell invocation without proper neutralization.

Detection Guidance

This vulnerability requires checking the version of Amazon SageMaker Distribution installed on your system. Use commands like 'aws sagemaker list-images' or check the Docker image tags for SageMaker Distribution. Compare the version against the affected ranges (2.8.x to 4.5.x) to determine exposure.

Impact Analysis

An attacker could gain access to another user's temporary execution role credentials, allowing them to invoke downstream AWS services on behalf of that user. This could lead to unauthorized data access, modification, or service usage within the compromised environment.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized access to another user's temporary execution role credentials and downstream AWS services. Unauthorized code execution in a regulated environment may lead to data breaches or unauthorized data processing, which are key concerns under these regulations.

Mitigation Strategies

Upgrade to a patched version of SageMaker Distribution (2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3). Restart Studio Spaces to apply updates. If using an unsupported minor line, migrate to a supported version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104019. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart