OS Command Injection Vulnerability in Amazon SageMaker by Amazon
CVE-2026-104019

9.3CRITICAL

Key Information:

Vendor

Aws

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104019?

An OS command injection vulnerability exists in the Studio Space startup validation script of Amazon SageMaker Distribution. This issue may allow an authenticated remote user with project contributor permissions to execute arbitrary commands within another project member's Studio Space. By exploiting a crafted connection resource property, the attacker can manipulate shell invocations to gain unauthorized access to another user’s temporary execution role credentials. To mitigate this risk, it is essential for users to upgrade to the specified safe versions depending on their currently deployed minor line. Users on unsupported minor lines must transition to a supported one, as no patches will be provided for end-of-life versions.

Affected Version(s)

sagemaker-distribution 2.8.0 < 2.14.12

sagemaker-distribution 3.3.0 < 3.9.12

sagemaker-distribution 4.0.0 < 4.0.11

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.