Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5709

33
FAUCET Score

OVERVIEW CVE-2026-5709 is an unsanitized input vulnerability in the FileBrowser API component of AWS Research and Engineering Studio (RES) affecting versions 2024.10 through 2025.12.01. The flaw enables remote authenticated attackers to execute arbitrary commands on the cluster-manager EC2 instance by supplying crafted input through the FileBrowser functionality. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and valid user credentials. The attack requires no user interaction and impacts all three security pillars: confidentiality, integrity, and availability are all rated as high. The FAUCET Risk Score of 52.0/100 indicates moderate concern within the assessed threat landscape. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is publicly available. The EPSS score of 0.001030 reflects very low probability of exploitation relative to other vulnerabilities. Remediation is straightforward: users should upgrade to RES version 2026.03 or apply the available mitigation patch to their existing installations.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026.03CPE matchmatch criteria
cpe:2.3:a:amazon:research_and_engineering_studio:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.09%
Probability of exploitation in next 30 days
EPSS Percentile
61.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0109 is in the 58th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

aws.amazon.com / security/security-bulletins/2026-014-aws
Vendor Advisory
github.com / aws/res/issues/150
ExploitIssue Tracking
github.com / aws/res/releases/tag/2026.03
Release Notes