CVE-2026-104019P2CRITICALCVSS 9.0≥ 2.8.0, < 2.14.12·≥ 3.3.0, < 3.9.12+5 more2026-10-02
CVE-2026-104019 [CRITICAL] CWE-78 CVE-2026-104019: OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contri
nvd