Executive brief
AWS Research and Engineering Studio is a cloud-based platform for collaborative research and development. A vulnerability in its authentication system could allow attackers to improperly access private encryption keys used to secure user data and communications, potentially leading to unauthorized access to sensitive research data and customer information stored within the service.
Technical details
The vulnerability is an improper link resolution flaw in the Auth.GetUserPrivateKey function within AWS Research and Engineering Studio. The root cause involves insecure handling of symbolic links or path resolution that could allow an attacker to retrieve private authentication keys. This appears to be exploitable through network access to the affected authentication mechanism. An attacker could leverage this to obtain private keys, potentially bypassing authentication controls or gaining unauthorized access to encrypted data. AWS has published a security bulletin but patch details and availability are not fully specified in the provided content.
Affected products
- Amazon Web Services AWS Research and Engineering Studio
Timeline
- 2026-09-22: disclosed