CVE-2026-104019: OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio

Published Oct 2, 2026
·
Updated

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution role credentials via a crafted connection resource property that is interpolated into a shell invocation without neutralization.

To remediate this issue, users should upgrade to version 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3, as applicable to the minor line in use. Users on minor lines that have reached end of support must move to a supported minor line, because no patched version will be released for those lines. In Amazon SageMaker Unified Studio, Studio Spaces adopt the latest patch of their minor line on restart once the patched images are deployed, so no version selection is required.

Affected Software

1 affected component
Amazon SageMaker Distribution<2.14.12, <3.9.12, <4.0.11, <4.1.11, <4.2.8, <4.3.5, <4.4.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 2.14.12
  2. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 3.9.12
  3. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 4.0.11
  4. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 4.1.11
  5. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 4.2.8
  6. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 4.3.5
  7. Upgrade

    Upgrade Amazon SageMaker Distribution to a version that resolves this vulnerability.

    Fixed in 4.4.3

Event History

Oct 2, 2026
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and what access do they need?

An authenticated remote user with project contributor permissions could exploit it. Exploitation requires crafting a connection resource property that reaches the vulnerable shell invocation during Studio Space startup validation.

2

What is the potential impact on other project members?

An attacker could execute arbitrary commands in another project member's Studio Space. They could also obtain that member's temporary execution role credentials.

3

Which Amazon SageMaker Distribution versions are fixed?

Fixed releases are 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3, according to the applicable minor line. Minor lines that have reached end of support must be moved to a supported minor line because they will not receive a patch.

4

What operational action is needed after patched images are available in Amazon SageMaker Unified Studio?

Restart Studio Spaces. They adopt the latest patch for their existing minor line after restart, with no version selection required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203