OVERVIEW CVE-2026-5709 is an unsanitized input vulnerability in the FileBrowser API component of AWS Research and Engineering Studio (RES) affecting versions 2024.10 through 2025.12.01. The flaw enables remote authenticated attackers to execute arbitrary commands on the cluster-manager EC2 instance by supplying crafted input through the FileBrowser functionality. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and valid user credentials. The attack requires no user interaction and impacts all three security pillars: confidentiality, integrity, and availability are all rated as high. The FAUCET Risk Score of 52.0/100 indicates moderate concern within the assessed threat landscape. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is publicly available. The EPSS score of 0.001030 reflects very low probability of exploitation relative to other vulnerabilities. Remediation is straightforward: users should upgrade to RES version 2026.03 or apply the available mitigation patch to their existing installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.03CPE matchmatch criteria | cpe:2.3:a:amazon:research_and_engineering_studio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.