PT-2026-30746 · Amazon Web Services · Research/Engineering Studio

Julianallenderussek

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5708

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AWS Research and Engineering Studio (RES) versions prior to 2026.03
Description An issue exists in the session creation component of AWS Research and Engineering Studio (RES) where unsanitized control of user-modifiable attributes could allow an authenticated remote user to escalate privileges. Successful exploitation could allow an attacker to assume the virtual desktop host instance profile permissions and interact with AWS resources and services via a crafted API request.
Recommendations Upgrade to RES version 2026.03 or apply the corresponding mitigation patch.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-5708

Affected Products

Research/Engineering Studio