PT-2026-56206 · Aws · Research/Engineering Studio
CVE-2026-14904
·
Published
2026-07-07
·
Updated
2026-07-07
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AWS Research and Engineering Studio (RES) versions prior to 2026.06
Description
An improper link resolution issue exists in the 'Auth.GetUserPrivateKey' API. An authenticated remote user can read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id rsa) with a symbolic link targeting any file on the host. Since the cluster-manager process operates with root privileges, any file accessible by root, such as other users' SSH private keys and application configuration secrets, is exposed.
Recommendations
Upgrade to RES version 2026.06.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Research/Engineering Studio