In plain language
What this advisory means
Amazon SageMaker Unified Studio lets teams work together on AI and data projects. A vulnerability was found in how SageMaker Spaces start up, where unsafe handling of network connection details could let a user run harmful commands in another team member's workspace. This could expose sensitive access credentials when a special security feature is enabled, allowing attackers to act as others. AWS fixed this by improving input handling, and the fix is automatically applied when SageMaker Spaces restart on supported software versions.
Technical explanation
How the issue affects the environment
CVE-2026-104019 is an OS command injection vulnerability in the startup script of SageMaker Spaces within Amazon SageMaker Unified Studio. During startup, a script validates network connections associated with a project. Improper sanitization of connection details can lead to arbitrary code execution within the context of another project member's Space. In projects with Trusted Identity Propagation enabled, this could let a user with at least project contributor rights access temporary execution role credentials of other members, enabling calls to downstream AWS services with delegated identity. AWS addressed the issue by sanitizing connection details in the startup validation process. The fix is deployed globally across supported SageMaker Distribution versions and takes effect on the next Space startup.
Operational impact
Why teams should care
This vulnerability allows malicious project contributors to execute arbitrary code in other members' environments and potentially assume their temporary credentials. This risks unauthorized access to resources and sensitive data, undermining trust and security within teams using SageMaker Spaces. Exploitation could lead to data breaches, misuse of downstream AWS services, and operational disruptions. Organizations must update and restart affected Spaces to restore secure operation and protect valuable intellectual property and credentials.
Immediate action
AWS customers should ensure their SageMaker Spaces run on patched SageMaker Distribution versions: 2.14.12 or later, 3.9.12 or later, and corresponding 4.x patched versions. Since SageMaker Spaces automatically update on restart, customers must restart their Spaces to apply the fix. No manual version selection is needed. Spaces running end-of-support versions with no fix need upgrading to supported patched versions.
Affected and fixed releases
Temporary risk reduction
No workarounds are provided by AWS. The only mitigation is applying the fix by upgrading to supported versions and restarting SageMaker Spaces.
Evidence and validation checklist
- AWS Security Bulletins official advisory page
- Version impact and fix information from AWS bulletin
- Description of vulnerability technical details
- Recommended remediation actions from AWS
- CVE identifier and references from AWS
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
