AWS Fixes SageMaker Studio Space Startup Command Injection

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

AWS published 2026-125-AWS for Amazon SageMaker Unified Studio and SageMaker Distribution Studio Spaces. AWS corrected command injection in Studio Space startup validation that could let a project member execute code in another member's Space; where TIPC is available, temporary execution-role credentials could also be exposed. AWS states that no workaround is available; supported versions were fixed server-side and affected Spaces must be restarted.

Confirm Scope And Apply The Supported Fix

What to do now: Identify Amazon SageMaker Unified Studio and SageMaker Distribution Studio Spaces, match the exact affected release and exposed workflow, apply the supported fix, validate operations, and preserve change and investigation evidence.

Open the authoritative advisory

Last verified: 2026-10-03 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeAmazon SageMaker Unified Studio and SageMaker Distribution Studio Spaces
Advisory2026-125-AWS
CVECVE-2026-104019
Authoritative release date2026-10-02 20:00:00 UTC (AWS bulletin publication time)
Authority revision date2026-10-02 20:00:00 UTC (latest authority revision verified for this run)
Affected versionsSageMaker Distribution 2.8.x–2.13.x and 3.3.x–3.8.x are affected and end of support; 2.14.x before 2.14.12, 3.9.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3 are affected. Version 4.5.x, versions before 2.8.x, and versions before 3.3.x are not affected.
Fixed versionSageMaker Distribution 2.14.12 / 3.9.12 / 4.0.11 / 4.1.11 / 4.2.8 / 4.3.5 / 4.4.3 or 4.5.x
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

AWS corrected command injection in Studio Space startup validation that could let a project member execute code in another member's Space; where TIPC is available, temporary execution-role credentials could also be exposed.

What To Validate Now

  1. Inventory. Locate Amazon SageMaker Unified Studio and SageMaker Distribution Studio Spaces deployments, versions, enabled features, exposure paths, owners, and dependent services.
  2. Establish applicability. Inventory SageMaker Unified Studio projects and Spaces, match each SageMaker Distribution line to AWS's exact affected table, identify project membership and TIPC exposure, and do not infer applicability from the service name alone.
  3. Remediate. Restart affected Spaces so the server-side fix is applied and move end-of-support 2.8.x–2.13.x and 3.3.x–3.8.x deployments to a supported fixed line. AWS states that no workaround is available.
  4. Validate. Confirm each restarted Space uses the fixed distribution build, test startup and notebook workflows, review project and execution-role activity for anomalies, rotate temporary or downstream credentials if investigation supports exposure, and retain evidence.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Coordinate Space restarts to protect unsaved work, validate package and notebook compatibility before changing distribution lines, preserve CloudTrail and workload logs before remediation, and distinguish an affected version from evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.