CVE-2026-14904
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS.
Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users' SSH private keys and application configuration secrets.
It's recommended to upgrade to RES version 2026.06.
CSIRTS triage
- What
- An improper link resolution issue could allow an authenticated remote user to read arbitrary files.
- Who is affected
- Users of AWS Research and Engineering Studio with the affected version.
- Urgency
- Remediation is important due to the potential for sensitive data exposure.
- Action
- Update to a version greater than 2026.03.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-14904
Get an email if CVE-2026-14904 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-14904)