Desk · AI systems and model risk

AI Security

Coverage of AI application security, model abuse, agentic systems, and data exposure.

Articles
63
Topics
20
Page
2 / 8
CVE-2026-104019 SageMaker Distribution: CVSS 3.1 9.0 CNA-scored and 4.0 9.3, no workaround, seven fixed lines, no exploitation reported.
highAI SecurityCve 2026 104019

AWS Patches Critical SageMaker Distribution Flaw That Lets a Project Contributor Hijack Another User's Studio Space

AWS disclosed CVE-2026-104019 on 2 October 2026 (bulletin 2026-125-AWS), an OS command injection in the Studio Space startup validation script of Amazon SageMaker Distribution as used by SageMaker Unified Studio. An authenticated project contributor can run commands in another project member's Space and take that member's temporary execution role credentials. The CNA scores it 9.0 (CVSS 3.1) and 9.3 (CVSS 4.0). AWS lists no workaround, and two older release families get no fix. We found no report of exploitation.

· 5 min