CODERED VTA

Command Injection Flaw in Amazon SageMaker Studio Spaces Exposes Project Member Credentials

High
Data centre floor
Photo by Javier Salinas on WordPress Photo Directory

AWS has published security bulletin 2026-125-AWS covering CVE-2026-104019, an OS command injection issue in the Studio Space startup script shipped with Amazon SageMaker Distribution. The flaw sits in SageMaker Unified Studio, the AWS service that brings data, analytics and AI development tooling together under shared projects. Because the weakness lives in the image that backs every Studio Space, any organisation running an affected SageMaker Distribution version inside Unified Studio is in scope. AWS rates the bulletin as Important, meaning it requires attention, and published it on 10 February 2026. Affected builds span the 2.8.x through 2.13.x and 3.3.x through 3.8.x lines, which are end of support and will receive no fix, along with 2.14.x before 2.14.12, 3.9.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5 and 4.4.x before 4.4.3. Versions 4.5.x and anything older than 2.8.0 or 3.3.0 are not affected.

When a SageMaker Space starts, its startup script runs a network validation check against every SageMaker connection available in the project. Connection details were not properly sanitised during this validation, so under certain conditions crafted connection data could cause arbitrary code to run inside the Space belonging to another project member. No working exploit path or proof-of-concept detail has been published beyond that description. In projects where the Trusted Identity Propagation feature is enabled, the consequence is that a user holding project contributor permissions or higher could reach another member's temporary execution role credentials. Those credentials could then be used to call downstream trusted identity propagation enabled AWS services on that member's behalf.

The strategic concern is the collapse of the boundary between project members who are nominally peers. Trusted Identity Propagation exists precisely so downstream services see the real human identity behind a query, and borrowed execution role credentials turn that audit trail into a liability rather than a control, since actions would appear to originate from the impersonated user. Shared analytics projects routinely sit on top of governed data lakes and warehouses, so the blast radius follows whatever the impersonated member was entitled to read. There is no workaround, and the two end of support branches will stay vulnerable permanently. On current exploitation status, FIRST EPSS puts CVE-2026-104019 at a 1.4 percent probability of exploitation in the next 30 days, and no exploitation of this issue has been reported.

Attack Surface

Cloud Service, Workspace

Tactics

Execution, Credential Access, Privilege Escalation, Lateral Movement

Techniques

  • T1059 – Command and Scripting Interpreter
  • T1528 – Steal Application Access Token
  • T1550.001 – Use Alternate Authentication Material: Application Access Token
  • T1078.004 – Valid Accounts: Cloud Accounts

SuperPRO's Threat Countermeasures Procedures

  1. Restart all SageMaker Studio Spaces running the affected minor lines so they pick up the patched images – Studio Spaces in SageMaker Unified Studio adopt the latest patch of their minor line on restart, so no manual version selection is needed.
  2. Confirm the SageMaker Distribution build behind each Space is at or above the fixed releases named in AWS bulletin 2026-125-AWS: 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5 or 4.4.3, or on the unaffected 4.5.x line.
  3. Migrate any Space still pinned to SageMaker Distribution 2.8.x to 2.13.x or 3.3.x to 3.8.x onto a supported line, as these branches are end of support and will receive no fix for CVE-2026-104019.
  4. Review which projects have the Trusted Identity Propagation feature enabled and re-check the membership list on those projects, since project contributor permissions or higher is the privilege level that could reach another member's temporary execution role credentials.
  5. Audit CloudTrail for calls to trusted identity propagation enabled downstream services where the propagated user identity does not match the Space or session that issued the request, and alert on execution role credentials used from an unexpected Space.
  6. Inspect SageMaker project connection definitions for connection detail fields containing shell metacharacters such as semicolons, backticks or $( ) sequences, as the flaw stems from unsanitised connection details consumed by the Space startup network validation.
  7. Reduce standing contributor-level membership on SageMaker Unified Studio projects that hold sensitive governed data, so that fewer identities meet the contributor-or-higher permission threshold described for this issue; no workaround exists other than the patched images.

Source

Code Red Cyber / VTA – coderedcyber.ai