Junglewise Threat Intelligence

CVE-2026-5709: AWS Research and Engineering Studio command injection in FileBrowser API

CVE-2026-5709 · Severity: high · CVSS 8.8 · Published 2026-04-06

Technologies: Amazon Research, Amazon Engineering Studio. Vendors: AWS, Amazon.

Executive brief

AWS Research and Engineering Studio (RES), a portal used by administrators to manage cloud-based research environments, contains a security flaw in its file browsing interface. An authorized user could exploit this vulnerability to run unauthorized commands on the central management server. This could lead to a full system takeover, potentially compromising research data, disrupting operations, or allowing further access into the cloud environment.

Technical details

An OS command injection vulnerability (CWE-78) exists in the FileBrowser List Files API of AWS Research and Engineering Studio (RES). The root cause is the failure to sanitize file path parameters, which allows shell meta-characters to be processed by the underlying operating system. An authenticated remote attacker can exploit this by sending crafted input to the FileBrowser functionality to execute arbitrary commands on the cluster-manager EC2 instance. The vulnerability affects versions 2024.10 through 2025.12.01 and is resolved in version 2026.03. Mitigation patches are also available for existing environments.

Affected products

  • AWS Research and Engineering Studio (RES) 2024.10 through 2025.12.01

Timeline

  • 2026-03-10: disclosed: Issue reported on GitHub
  • 2026-03-26: patched: RES version 2026.03 released
  • 2026-04-06: advisory: AWS security bulletin published

References

Related threats