PT-2026-84375 · Amazon · Amazon Sagemaker Python Sdk

CVE-2026-83551

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Amazon SageMaker Python SDK versions prior to 3.11.0 Amazon SageMaker Python SDK versions prior to 2.256.0
Description Sensitive information is stored in cleartext within the @step and @remote decorator pipeline components. This allows an authenticated remote user to extract the HMAC (Hash-based Message Authentication Code) signing key from the 'DescribePipeline' API endpoint responses. By obtaining this key, an attacker can forge valid integrity signatures for specially crafted function payloads, leading to code execution within the pipeline execution context of another user in the same AWS account.
Recommendations Update Amazon SageMaker Python SDK to version 3.11.0 or later. Update Amazon SageMaker Python SDK to version 2.256.0 or later.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83551
GHSA-7XMC-CRRW-FV5R

Affected Products

Amazon Sagemaker Python Sdk