LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-5707 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 6, 2026

AWS Research and Engineering Studio - Command Injection

Published: April 6, 2026Updated: April 6, 2026Remote Exploitable

Overview

AWS Research and Engineering Studio (RES) 2025.03 through 2025.12.01 contains a command injection caused by unsanitized input in virtual desktop session name handling, letting remote authenticated actors execute arbitrary commands as root, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Remote authenticated actors can execute arbitrary commands as root, leading to full system compromise.

Mitigation

Upgrade to RES version 2026.03 or apply the corresponding mitigation patch.

Details

CVE ID
CVE-2026-5707
Severity
High
CVSS Score
8.8
Type
command_injection
Status
new

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H