External risk intelligence

OS Command Injection in SageMaker Studio Spaces Allows Project Member Credential Theft.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-104019

The vulnerability resides within an internal Studio Space startup validation script in Amazon SageMaker Distribution. While it involves a network-accessible service, it requires the attacker to be an authenticated user with specific project contributor permissions within the platform, making direct public-internet exposure of this specific functional flaw unlikely in typical deployments.

OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in the Studio Space startup validation script for Amazon SageMaker Distribution. This issue could allow an authenticated user with project contributor permissions to execute arbitrary commands within another user's Studio Space, potentially leading to the compromise of temporary execution role credentials. The primary concern is to confirm if your environment utilizes the affected versions and is exposed to this specific risk.

  • Command execution risk in project collaboration.
  • Matters if authenticated users can be compromised.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker with project contributor permissions could exploit this vulnerability by creating a malicious connection resource. This crafted resource would be used to inject commands into another project member's Studio Space, potentially allowing the attacker to execute arbitrary commands and steal temporary execution role credentials.

  • Authenticated user with project contributor access.
  • Crafted connection resource property.
  • Execute commands, steal credentials.

Live Threat

Current exploitation, exposure, and threat context

An authenticated remote user with project contributor permissions could execute arbitrary commands within another member's Studio Space. This could occur when a crafted connection resource property is interpolated into a shell invocation without proper neutralization, potentially exposing temporary execution role credentials.

  • Project member data at risk.
  • Command injection via crafted resource property.
  • Exposure of temporary execution role credentials.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Studio Space startup script in Amazon SageMaker Distribution is susceptible to OS command injection, potentially impacting authenticated users with project contributor permissions. The first practical step is to identify all instances of the affected technology, confirm their reachability and criticality, and then assign ownership for remediation planning.

  • Assign ownership to the SageMaker or platform team.
  • Verify Studio Space configurations and member permissions.
  • Plan upgrade or migration based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Amazon SageMaker Distribution and how is it used?

Amazon SageMaker Distribution provides a collection of popular machine learning frameworks and libraries pre-configured for use in Amazon SageMaker. It serves as the foundation for Studio Spaces in SageMaker Unified Studio, allowing data scientists and developers to run experiments, build models, and collaborate within a shared environment.

What does OS command injection mean for CVE-2026-104019?

This vulnerability is an OS command injection flaw (CWE-78). It means the software fails to sanitize input, allowing a user to insert malicious operating system commands into a script. In this specific case, the flaw allows unauthorized code to execute within another person's Studio Space session, effectively letting an attacker run commands as if they were that user.

What must happen for this vulnerability to be triggered?

An attacker must already have authenticated access to the system with project contributor permissions. They exploit the flaw by providing a specifically crafted connection resource property during the Studio Space startup process. This issue is not triggered by public-internet traffic or anonymous users; it requires an active, authenticated member of the project to act maliciously.

Is my SageMaker environment at risk?

Halo Surface Signal indicates that while the service is network-accessible, direct public exposure is unlikely because the flaw exists within an internal startup script. You should be most concerned if your organization uses SageMaker Unified Studio where multiple users share project contributor roles. The risk level depends on your internal access controls and trust between project members.

How do I start addressing this security issue?

First, identify which minor version of SageMaker Distribution your team is using. If you are on an affected version, coordinate with your platform team to upgrade to the specified patched release for your minor line. For SageMaker Unified Studio users, triggering a restart of the Studio Space after the patched images are deployed will ensure the updated startup script is applied.

References