CVE-2026-83551
Published:September 01, 2026
Updated:September 02, 2026
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.
Affected Packages
sagemaker (CONDA):
Affected version(s) >=3.5.0 <3.11.0Fix Suggestion:
Update to version 3.11.0sagemaker (CONDA):
Affected version(s) >=2.72.3 <2.256.0Fix Suggestion:
Update to version 2.256.0sagemaker (PYTHON):
Affected version(s) >=1.0.0 <2.256.0Fix Suggestion:
Update to version 2.256.0sagemaker (PYTHON):
Affected version(s) >=3.0 <3.11.0Fix Suggestion:
Update to version 3.11.0Related Resources (4)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.5
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
HIGH
Subsequent System Availability
HIGH
CVSS v3
Base Score:
7.2
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
Cleartext Storage of Sensitive Information