CVE-2026-5709Disclosure(amazon / research_and_engineering_studio)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch amazon research_and_engineering_studio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • research_and_engineering_studio

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
research_and_engineering_studio

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-07: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 104-0604-0704-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-061
Disclosure1
2026-04-071
Disclosure1
2026-04-161
Patch1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5709 Remote Command Execution in AWS Research and Engineering Studio FileBrowser API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5709

    Post summary

    The post announces CVE‑2026‑5709, a Remote Command Execution flaw in AWS RE Studio’s FileBrowser API, and provides a link to a vulnerability details page, without offering PoC, exploit code, patches, or evidence of active exploitation.

    1001056
    4.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    AWS、Research and Engineering Studioの3件の脆弱性を修正(CVE-2026-5707,CVE-2026-5708,CVE-2026-5709) https://rocket-boys.co.jp/security-measures-lab/aws-research-engineering-studio-3-flaws-fixed/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces that AWS Research and Engineering Studio has fixed three vulnerabilities (CVE‑2026‑5707, CVE‑2026‑5708, CVE‑2026‑5709), linking to a site for more information.

    0000084
    380 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5709 Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to exe… https://www.cve.org/CVERecord?id=CVE-2026-5709

    Post summary

    The post announces CVE-2026-5709, noting that unsanitized input in the AWS RES FileBrowser API could let authenticated users execute commands.

    00000186
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonresearch_and_engineering_studio---

Explore more