Amazon Research And Engineering Studio vulnerabilities
3 known vulnerabilities affecting amazon/research_and_engineering_studio.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2026-5707P2HIGHCVSS 8.8fixed in 2026.032026-04-06
CVE-2026-5707 [HIGH] CWE-78 CVE-2026-5707: Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name.
To remediate this issue, users are advised to upgrade to RES
nvd
CVE-2026-5709P2HIGHCVSS 8.8fixed in 2026.032026-04-06
CVE-2026-5709 [HIGH] CWE-78 CVE-2026-5709: Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.1
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality.
To remediate this issue, users are advised to upgrade to RES versio
nvd
CVE-2026-5708P2HIGHCVSS 8.8fixed in 2026.032026-04-06
CVE-2026-5708 [HIGH] CWE-915 CVE-2026-5708: Unsanitized control of user-modifiable attributes in the session creation component in AWS Research
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and services via a crafted API request.
To
nvd