{"id":"CVE-2026-5707","title":"Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…","summary":"Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"amazon","product":"research_and_engineering_studio","affected":["research_and_engineering_studio < 2026.03"],"patched":["research_and_engineering_studio 2026.03"],"published":"2026-04-06","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5707","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-014-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/res/issues/151","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/res/releases/tag/2026.03","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd"],"epss":0.00994,"epssPercentile":0.60605,"ingestedAt":"2026-07-24T09:23:52.500Z","slug":"CVE-2026-5707","body":"## Overview\n\nUnsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name.\n\nTo remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.\n\n## Affected\n\n- `research_and_engineering_studio < 2026.03`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `research_and_engineering_studio 2026.03`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}