Executive brief
AWS Research and Engineering Studio (RES) is a web portal used by administrators to manage secure cloud-based research and engineering environments. A security vulnerability in how the portal handles virtual desktop session names allows an authorized user to execute malicious commands with administrative (root) privileges on the underlying host. This could lead to a complete takeover of the virtual desktop environment and unauthorized access to sensitive research data.
Technical details
An OS command injection vulnerability exists in AWS Research and Engineering Studio (RES) versions 2025.03 through 2025.12.01. The vulnerability stems from improper neutralization of special elements within the 'session name' field. When a Virtual Desktop Infrastructure (VDI) session is stopped and resumed, the system executes an AWS Systems Manager (SSM) command on the EC2 instance that includes the unsanitized session name. A remote authenticated attacker can exploit this by creating a crafted session name containing shell metacharacters to execute arbitrary commands with root privileges on the virtual desktop host. The issue is resolved in RES version 2026.03, and manual mitigation patches are available for older versions.
Affected products
- AWS Research and Engineering Studio (RES) 2025.03 through 2025.12.01
CVE identifiers
- CVE-2026-5709
- CVE-2026-5708
- CVE-2026-5707
Timeline
- 2026-03-10: disclosed: Issue reported on GitHub repository
- 2026-03-26: patched: RES version 2026.03 released
- 2026-04-06: advisory: AWS security bulletin published