Junglewise Threat Intelligence

CVE-2026-5708: AWS Research and Engineering Studio privilege escalation in session creation

CVE-2026-5708 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Amazon Web Services Research and Engineering Studio, Amazon Research, Amazon Engineering Studio. Vendors: AWS, Amazon Web Services, Amazon.

Executive brief

AWS Research and Engineering Studio (RES) is a web portal used by administrators to manage secure cloud-based research environments. A security flaw in the session creation tool allows an authorized user to gain higher-level permissions than intended. By exploiting this, an attacker could take control of the virtual desktop's identity to access other sensitive AWS resources and services within the organization's cloud environment.

Technical details

A privilege escalation vulnerability (CWE-915) exists in the session creation component of AWS Research and Engineering Studio (RES). The root cause is the lack of sanitization for user-modifiable attributes, specifically allowing users to provide an external 'instance_profile_arn' when calling the CreateSession API. An authenticated remote attacker can exploit this by sending a crafted API request to replace the default instance profile with one of their choosing. This allows the attacker to assume the permissions of the injected instance profile, potentially gaining unauthorized access to broader AWS resources and services. The issue is resolved in RES version 2026.03, and manual patches are available for older versions.

Affected products

  • AWS Research and Engineering Studio (RES) 2023.11 through 2025.12.01

Timeline

  • 2026-03-10: disclosed: Issue opened on GitHub repository
  • 2026-03-26: patched: Version 2026.03 released with security fixes
  • 2026-04-06: advisory: AWS security bulletin and CVE published

References

Related threats