PT-2026-84375 · Amazon · Amazon Sagemaker Python Sdk
CVE-2026-83551
·
Published
2026-09-01
·
Updated
2026-09-01
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Amazon SageMaker Python SDK versions prior to 3.11.0
Amazon SageMaker Python SDK versions prior to 2.256.0
Description
Sensitive information is stored in cleartext within the
@step and @remote decorator pipeline components. This allows an authenticated remote user to extract the HMAC (Hash-based Message Authentication Code) signing key from the 'DescribePipeline' API endpoint responses. By obtaining this key, an attacker can forge valid integrity signatures for specially crafted function payloads, leading to code execution within the pipeline execution context of another user in the same AWS account.Recommendations
Update Amazon SageMaker Python SDK to version 3.11.0 or later.
Update Amazon SageMaker Python SDK to version 2.256.0 or later.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Sagemaker Python Sdk