PT-2026-42823 · Amazon · Amazon Braket Sdk
CVE-2026-9291
·
Published
2026-05-22
·
Updated
2026-07-23
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Amazon Braket SDK versions prior to 1.117.0
Description
Insecure deserialization in the job results processing component may allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code.
Recommendations
Upgrade to version 1.117.0 or later.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Braket Sdk