CVE-2026-104019: OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization.
To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 2.14.12 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 3.9.12 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 4.0.11 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 4.1.11 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 4.2.8 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 4.3.5 - Upgrade
Upgrade
Amazon SageMaker Distributionto a version that resolves this vulnerability.Fixed in 4.4.3
Event History
Frequently Asked Questions
Who can exploit this issue, and what access do they need?
An authenticated remote user with project contributor permissions could exploit it. Exploitation requires crafting a connection resource property that reaches the vulnerable shell invocation during Studio Space startup validation.
What is the potential impact on other project members?
An attacker could execute arbitrary commands in another project member's Studio Space. They could also obtain that member's temporary execution role credentials.
Which Amazon SageMaker Distribution versions are fixed?
Fixed releases are 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3, according to the applicable minor line. Minor lines that have reached end of support must be moved to a supported minor line because they will not receive a patch.
What operational action is needed after patched images are available in Amazon SageMaker Unified Studio?
Restart Studio Spaces. They adopt the latest patch for their existing minor line after restart, with no version selection required.