CVE-2026-5709: AWS Research and Engineering Studio (RES) FileBrowser Command Injection
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality.
To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.03 - Compensating control
Apply the corresponding mitigation patch to the existing AWS Research and Engineering Studio (RES) environment (v2024.10 through 2025.12.01) if you cannot upgrade to RES version 2026.03.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5709?
CVE-2026-5709 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2026-5709?
To fix CVE-2026-5709, upgrade AWS Research and Engineering Studio to version 2026.03 or later.
Who is affected by CVE-2026-5709?
Users of AWS Research and Engineering Studio versions 2024.10 through 2025.12.01 are affected by CVE-2026-5709.
What type of vulnerability is CVE-2026-5709?
CVE-2026-5709 is classified as a command injection vulnerability.
Can CVE-2026-5709 be exploited remotely?
Yes, CVE-2026-5709 can be exploited remotely by an authenticated actor.