CVE-2026-5708 Details
Description
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and services via a crafted API request. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
A privilege escalation vulnerability has been identified in AWS Research and Engineering Studio (RES) versions prior to 2026.03. This vulnerability allows an authenticated remote user to manipulate user-modifiable attributes in the session creation component, potentially escalating privileges and assuming the virtual desktop host instance profile permissions. Exploitation of this vulnerability could enable interaction with AWS resources and services through a crafted API request.
Users are advised to upgrade to AWS Research and Engineering Studio version 2026.03 or apply the corresponding mitigation patch to their existing environment. Instructions for applying the patch are available on the AWS RES GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-014-aws/ | AMZN | Vendor Advisory |
| https://github.com/aws/res/issues/149 | AMZN | ExploitIssue TrackingMitigation |
| https://github.com/aws/res/releases/tag/2026.03 | AMZN | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon research and engineering studio | < 2026.03 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | New CVE Received | AMZN |