CVE-2026-5707

HIGH

Command Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES)

Title source: cna
STIX 2.1

Description

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0099
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
amazon/research_and_engineering_studio < 2026.03
AWS/Research and Engineering Studio (RES) 2025.03 - 2025.12.01
Published Apr 06, 2026
Tracked Since Apr 07, 2026