← Back to CVE search

CVE-2026-14904

AWS Research and Engineering Studio

Description

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users- SSH private keys and application configuration secrets. It-s recommended to upgrade to RES version 2026.06.

CVSS 6.5EPSS 0.381%Risk 0.67
View source
Published
2026-07-07 17:16:35
Affected versions
<2026.06
Type
Other
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N