AWS Research and Engineering Studio: Critical Symlink Vulnerability Requires Immediate Update
AWS Research and Engineering Studio (RES) versions 2026.03 and earlier contain a nasty symlink resolution bug (CVE-2026-14904) in the Auth.GetUserPrivateKey API. An authenticated attacker can swap their SSH private key with a symbolic link to read arbitrary files on the cluster-manager instance—including other users' keys and secrets—since the process runs as root. Update to the latest version immediately if you're running RES.