PT-2026-42823 · Amazon · Amazon Braket Sdk

CVE-2026-9291

·

Published

2026-05-22

·

Updated

2026-07-23

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Amazon Braket SDK versions prior to 1.117.0
Description Insecure deserialization in the job results processing component may allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code.
Recommendations Upgrade to version 1.117.0 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9291
GHSA-G697-2XRC-GC46
PYSEC-2026-2342

Affected Products

Amazon Braket Sdk