Cleartext Storage Vulnerability in Amazon SageMaker Python SDK
CVE-2026-83551

8.5HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
1 September 2026

What is CVE-2026-83551?

The Amazon SageMaker Python SDK prior to v3.11.0 and v2.256.0 has a vulnerability where sensitive information, including HMAC signing keys, is stored in cleartext within the @step and @remote decorator pipeline components. This exposure allows authenticated remote users to access the HMAC signing key from SageMaker DescribePipeline API responses. Consequently, they can forge valid integrity signatures for maliciously crafted function payloads, potentially executing unauthorized code in another user's pipeline execution context within the same AWS account.

Affected Version(s)

sagemaker-python-sdk 0 < 3.11.0

sagemaker-python-sdk 0 < 2.256.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.