PT-2026-30746 · Amazon Web Services · Research/Engineering Studio

·

CVE-2026-5708

·

Published

2026-04-06

·

Updated

2026-04-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AWS Research and Engineering Studio (RES) versions prior to 2026.03
Description An issue exists in the session creation component of AWS Research and Engineering Studio (RES) where unsanitized control of user-modifiable attributes could allow an authenticated remote user to escalate privileges. Successful exploitation could allow an attacker to assume the virtual desktop host instance profile permissions and interact with AWS resources and services via a crafted API request.
Recommendations Upgrade to RES version 2026.03 or apply the corresponding mitigation patch.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5708

Affected Products

Research/Engineering Studio