Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name.
To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.
{
"cwe_ids": [
"CWE-78"
],
"cna_assigner": "AMZN",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5707.json"
}{
"source": [
"AFFECTED_FIELD",
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "2025.03"
},
{
"last_affected": "2025.12.01"
},
{
"introduced": "0"
},
{
"fixed": "2026.03"
}
],
"cpe": "cpe:2.3:a:amazon:research_and_engineering_studio:*:*:*:*:*:*:*:*"
}