Amazon SageMaker Distribution: Critical Command Injection Vulnerability Requires Immediate Action
Amazon SageMaker Unified Studio has a nasty OS command injection bug (CVE-2026-104019) in the startup script that could let project members execute arbitrary code in other users' Spaces. With Trusted Identity Propagation enabled, attackers could snag temporary credentials and impersonate colleagues. AWS has patched supported versions (2.14.12+, 3.9.12+, 4.0.11+, 4.1.11+, 4.2.8+, 4.3.5+, 4.4.3+), deploying automatically on next Space startup. If you're running older versions, upgrade now—older branches are EOL with no fixes available.
source: [aws/security-bulletin]