CVE-2026-5707 Details
Description
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
A command injection vulnerability has been identified in AWS Research and Engineering Studio (RES) versions 2025.03 through 2025.12.01. The issue arises from unsanitized input in the virtual desktop session name management, which could allow a remote authenticated user to execute arbitrary commands as root on the virtual desktop host. This exploitation occurs when a session is stopped and resumed, as the session name is processed in a way that can execute embedded malicious commands on the associated EC2 instance.
Users are advised to upgrade to AWS RES version 2026.03 or apply the corresponding mitigation patch to their existing environment. Instructions for applying the patch are available on the AWS RES GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-014-aws/ | AMZN | Vendor Advisory |
| https://github.com/aws/res/issues/151 | AMZN | ExploitIssue Tracking |
| https://github.com/aws/res/releases/tag/2026.03 | AMZN | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon research and engineering studio | < 2026.03 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | New CVE Received | AMZN |