CVE-2026-1777Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Jobs S3 output location may have the ability to upload arbitrary artifacts which are executed the next time the Training Job is invoked.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-03: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 202-0202-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-032
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1777 The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob func… https://www.cve.org/CVERecord?id=CVE-2026-1777

    Post summary

    The Amazon SageMaker Python SDK releases before v3.2.0 and v2.256.0 expose the ModelBuilder HMAC signing key in cleartext within the DescribeTrainingJob response, constituting an information‑disclosure vulnerability.

    00010161
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-1777: SageMaker's Open Secret: How a Helper Function Became a Backdoor A critical design flaw in the Amazon SageMaker Python SDK allowed for Remote Code Execution (RCE) via insecure handling of cryptographic secrets. The SDK's 'remote functio... https://cvereports.com/reports/CVE-2026-1777

    Post summary

    Amazon SageMaker’s Python SDK contains a critical design flaw that permits RCE through insecure cryptographic secret handling, as disclosed by CVE‑2026‑1777.

    0000047
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1777 Amazon SageMaker SDK HMAC Signing Key Exposure in Training Job Response https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1777

    Post summary

    A new CVE (CVE-2026-1777) describing HMAC signing key exposure in Amazon SageMaker SDK training job responses has been disclosed, but no further details on exploitation, PoC, patch, or debunking are provided.

    0000067
    4.0K followersView on X

Explore more