CVE-2026-5707 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 6, 2026
AWS Research and Engineering Studio - Command Injection
Published: April 6, 2026Updated: April 6, 2026Remote Exploitable
Overview
AWS Research and Engineering Studio (RES) 2025.03 through 2025.12.01 contains a command injection caused by unsanitized input in virtual desktop session name handling, letting remote authenticated actors execute arbitrary commands as root, exploit requires authentication.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Remote authenticated actors can execute arbitrary commands as root, leading to full system compromise.
Mitigation
Upgrade to RES version 2026.03 or apply the corresponding mitigation patch.
References
Related Resources
Details
- CVE ID
- CVE-2026-5707
- Severity
- High
- CVSS Score
- 8.8
- Type
- command_injection
- Status
- new
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H