Skip to content
AWSAWS-2026-014

Issues with AWS Research and Engineering Studio (RES)

UnratedCVE-2026-5707 · Published Apr 6, 2026 · updated Sep 25, 2026

Bulletin ID:  2026-014-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/6/2026 2:00 PM PST Description: Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES). CVE-2026-5707 : Unsanitized input in an OS Command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. CVE-2026-5708 : Improper control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) before version 2026.03 might allow an authenticated remote user to escalate privileges and assume the Virtual Desktop Host instance profile permissions and interact with other AWS resources and services via a crafted API request. CVE-2026-5709 : Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (R...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID:  2026-014-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/6/2026 2:00 PM PST Description: Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES). CVE-2026-5707 : Unsanitized input in an OS Command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. CVE-2026-5708 : Improper control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) before version 2026.03 might allow an authenticated remote user to escalate privileges and assume the Virtual Desktop Host instance profile permissions and interact with other AWS resources and services via a crafted API request. CVE-2026-5709 : Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. Impacted versions :  Resolution: This issue has been addressed in RES version 2026.03 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds User can apply a patch to the existing RES environment following the mitigation instructions [ 2025.12.01 and earlier ] Preventing Command Injection via Session Name, [ 2025.12.01 and earlier ] Privilege Escalation via Instance Profile Injection, or [ 2025.12.01 and earlier ] Command injection via FileBrow.   Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-014-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} Issues with AWS Research and Engineering Studio (RES) Bulletin ID:  2026-014-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/6/2026 2:00 PM PST Description: Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES). CVE-2026-5707 : Unsanitized input in an OS Command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. CVE-2026-5708 : Improper control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) before version 2026.03 might allow an authenticated remote user to escalate privileges and assume the Virtual Desktop Host instanc

Severity from
no source yet
Also known as
CVE-2026-5708, CVE-2026-5709

More AWS advisories

All AWS
Advisory
Out-of-bounds Write in Firecracker virtio-pci Transport
UnratedApr 7
Issues with Amazon Athena ODBC Driver
UnratedApr 3
Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme
UnratedApr 2
AWS C Event Stream Streaming Decoder Stack Buffer Overflow
UnratedMar 31
Defense in depth enhancement for CloudFront signing utility in AWS Tools for PowerShell
High7.7Mar 26
Defense in depth enhancement for CloudFront signing utility in AWS SDK for .NET
High7.7Mar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.