CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK

Amazon Web Services Version 1 original current

Imported from official source

Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline component uses an HMAC key to protect the integrity of serialized function payloads stored in S3. We identified an issue where the HMAC secret key is stored in cleartext within pipeline definitions and accessible via the DescribePipeline API. This allows an actor with a role in that account that has permissions to invoke DescribePipeline to extract the key, create cloud-pickled payloads with valid HMACs, and overwrite S3 objects, achieving code execution in another user's pipeline execution context within the same AWS account. Impacted versions: - HMAC Configuration in SageMaker Python SDK v3 < v3.11.0 - HMAC Configuration in SageMaker Python SDK v2 < v2.256.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

This version

Version
1 of 1
Recorded
September 18, 2026 09:42
Change
Initial
Content hash
25239902a530c27e9508718806e34cba
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.