---
id: CVE-2026-5709
title: >-
  Unsanitized input in the FileBrowser API in AWS Research and Engineering
  Studio (RES) version 2024.10 through 2025.12.01 might allow a remote
  authenticated actor to execute arbitrary commands on the cluster-manager EC2
  instance via craft…
summary: >-
  Unsanitized input in the FileBrowser API in AWS Research and Engineering
  Studio (RES) version 2024.10 through 2025.12.01 might allow a remote
  authenticated actor to execute arbitrary commands on the cluster-manager EC2
  instance via craft…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: amazon
product: research_and_engineering_studio
affected:
  - research_and_engineering_studio < 2026.03
patched:
  - research_and_engineering_studio 2026.03
published: '2026-04-06'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5709'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-014-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/aws/res/issues/150'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/aws/res/releases/tag/2026.03'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
epss: 0.01087
epssPercentile: 0.63886
ingestedAt: '2026-07-24T09:23:52.548Z'
---

## Overview

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality.

To remediate this issue, users are advised to upgrade to RES version 2026.03 or apply the corresponding mitigation patch to their existing environment.

## Affected

- `research_and_engineering_studio < 2026.03`

## Remediation

Upgrade past the affected range:

- `research_and_engineering_studio 2026.03`
