SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-83551

HIGH · CVSS 7.2 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Amazon SageMaker Python SDK prior to versions 3.11.0 and 2.256.0 is vulnerable due to the cleartext storage of sensitive information in its decorator pipeline component. This flaw allows authenticated remote users to extract the HMAC signing key from API responses, potentially enabling them to forge valid integrity signatures and execute arbitrary code within another user's pipeline context. Organizations using these affected versions should prioritize remediation to prevent unauthorized access and execution risks within their AWS environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-83551
Severity
HIGH
CVSS
7.2
EPSS
0.38%

Original NVD Description

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.