AWS SageMaker Distribution CVE-2026-104019: code execution in Unified Studio Spaces, end-of-support versions left unfixed
EditorialBy TrustList Editorial
AWS bulletin 2026-125 fixes a flaw in SageMaker Unified Studio Space start-up that could run code in another project member's Space. Supported images are patched on restart; 2.8–2.13 and 3.3–3.8 are end of support and get no fix.
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- +2 more
About AWS SageMaker Distribution CVE-2026-104019: code execution in Unified Studio Spaces, end-of-support versions left unfixed
AWS SageMaker Distribution CVE-2026-104019: code execution in Unified Studio Spaces, end-of-support versions left unfixed
2 October 2026 — AWS published security bulletin 2026-125-AWS on 2 October 2026 for CVE-2026-104019 in SageMaker Distribution, the image that runs Spaces in Amazon SageMaker Unified Studio. AWS has deployed a fix for supported versions that applies when a Space restarts. Two ranges of older versions are end of support and will not be fixed.
Not yet independently verified. Only AWS's own bulletin has been read; no independent report had been found at 2026-10-04. We will update this when it can be confirmed, and remove this note.
What the flaw does
When a SageMaker Space starts, its start-up script validates the network against every SageMaker connection in the project. AWS says that, under certain conditions, connection details were not sanitised properly during this step, which could let arbitrary code run in the Space of another project member. In projects with Trusted Identity Propagation enabled, a user with project contributor permissions or higher could gain another member's temporary execution-role credentials and call downstream AWS services on that member's behalf.
Which versions
AWS lists:
- 2.8.x to 2.13.x: all affected, no fix (end of support)
- 2.14.x before 2.14.12: fixed in 2.14.12
- 3.3.x to 3.8.x: all affected, no fix (end of support)
- 3.9.x before 3.9.12: fixed in 3.9.12
- 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, 4.4.x before 4.4.3: fixed in those releases
- 4.5.x, and anything before 2.8.0 or 3.3.0: not affected
AWS lists no workaround.
What to do
- Restart every Space on a supported minor version. AWS says Spaces adopt the latest patch of their minor line on restart, so no version choice is needed.
- Find any Space or custom image on 2.8 to 2.13 or 3.3 to 3.8 and move it to a supported line, preferably 4.5, because those versions will stay vulnerable.
- In projects with Trusted Identity Propagation, review who holds contributor permissions and check CloudTrail for calls made with members' execution roles that they do not recognise.
Why it matters for buyers
Shared data and machine-learning workspaces put many users' credentials side by side, so a flaw that crosses from one member to another is a credential problem, not just a notebook problem. The end-of-support clause is the part to act on: teams that pinned older images for compatibility now carry an unfixable flaw until they upgrade.
Sources
Categories & features
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- Patch Management
- Machine Learning
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.