CVE-2026-5709
- EPSS 0.12%
- Veröffentlicht 06.04.2026 21:32:04
- Zuletzt bearbeitet 10.04.2026 20:03:29
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when...
CVE-2026-5708
- EPSS 0.07%
- Veröffentlicht 06.04.2026 21:28:03
- Zuletzt bearbeitet 10.04.2026 20:08:48
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host...
CVE-2026-5707
- EPSS 0.12%
- Veröffentlicht 06.04.2026 21:25:48
- Zuletzt bearbeitet 10.04.2026 20:16:05
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virt...