Vulnerability
Published 2026-10-02
Verified 2026-10-04

AWS SageMaker Distribution CVE-2026-104019 (CVSS 4.0 9.3): Studio Space startup OS command injection → peer Space RCE / TIP credentials; patch + restart Spaces

AWS Security Bulletin 2026-125-AWS (Important; published 2 October 2026 PDT) and Amazon CNA CVE-2026-104019 disclose OS command injection (CWE-78) in the Studio Space startup validation script in Amazon SageMaker Distribution when used with Amazon SageMaker Unified Studio. On Space startup the script network-validates available SageMaker connections in a project; improper sanitization of connection details can let an authenticated project contributor (or higher) execute arbitrary commands in another project member’s Studio Space. With Trusted Identity Propagation enabled, that can yield the peer’s temporary execution-role credentials and calls to TIP-enabled AWS services on their behalf. CVSS 4.0 9.3 Critical (Amazon CNA; also CVSS 3.1 9.0). Fixed images: 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, 4.4.3; 4.5.x not affected; 2.8–2.13 and 3.3–3.8 EOL with no fix — move to a supported minor. AWS says the fix is deployed globally; Unified Studio Spaces pick up the latest patch of their minor line on restart (no version picker). No workarounds; no exploitation reported in the bulletin. Primary: AWS 2026-125-AWS; also GHSA-w64x-664p-7w66.

Product
Amazon SageMaker Distribution / SageMaker Unified Studio Spaces
Versions
Affected: 2.8.x–2.13.x (EOL, no fix); 2.14.x < 2.14.12; 3.3.x–3.8.x (EOL, no fix); 3.9.x < 3.9.12; 4.0.x < 4.0.11; 4.1.x < 4.1.11; 4.2.x < 4.2.8; 4.3.x < 4.3.5; 4.4.x < 4.4.3. Not affected: 4.5.x; <2.8.0 and <3.3.0.
CVSS
(CVSS 4.0 Critical; Amazon CNA); 9.0 (CVSS 3.1 Critical)
Exploited in Australia?
unknown
Patch to
Restart Unified Studio Spaces on supported minors so they adopt 2.14.12 / 3.9.12 / 4.0.11 / 4.1.11 / 4.2.8 / 4.3.5 / 4.4.3 images. EOL 2.8–2.13 and 3.3–3.8: migrate to a supported minor. No workaround. Review TIP-enabled projects and rotate execution-role credentials if contributor-accessible connection properties were attacker-controlled.

Primary: AWS Security Bulletin 2026-125-AWS — SageMaker Distribution CVE-2026-104019 (2 Oct 2026) · Vendor: AWS — 2026-125-AWS (SageMaker Unified Studio / Distribution) · CVE: CVE-2026-104019 · GitHub Advisory GHSA-w64x-664p-7w66 — CVE-2026-104019

vulnerabilities cloud ai