
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1777 is an information disclosure vulnerability in the Amazon SageMaker Python SDK, where the ModelBuilder HMAC signing key is exposed in cleartext within the response elements of the DescribeTrainingJob API. Affected versions include SageMaker Python SDK v3 before v3.2.0 and v2 before v2.256.0. The vulnerability was disclosed on February 2, 2026, with patches released the same day (AWS Security Bulletin, GitHub Advisory). It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory).
The root cause is classified under CWE-319 (Cleartext Transmission of Sensitive Information) and CWE-201 (Insertion of Sensitive Information Into Sent Data). The SageMaker SDK's remote functions feature uses a per-job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3; however, this key is stored in environment variables and returned in plaintext via the DescribeTrainingJob API response (AWS Security Bulletin, GitHub Advisory). An attacker with DescribeTrainingJob API permissions can retrieve the HMAC key, forge cloud-pickled (serialized) payloads with valid HMACs, and overwrite S3 objects at the Training Job's output location — bypassing integrity validation entirely. Exploitation requires two concurrent permissions: the ability to call DescribeTrainingJob and write access to the Training Job's S3 output location (GitHub Advisory).
Successful exploitation enables arbitrary code execution in the victim's Python process when the Training Job results are retrieved, as tampered payloads are deserialized without triggering integrity validation errors (GitHub Advisory). This can lead to compromise of training data, model poisoning, exposure of sensitive environment variables and AWS metadata, and unauthorized access to compute resources. In multi-tenant or shared S3 bucket environments, the exposed HMAC key can serve as a pivot point to compromise adjacent users' remote function workloads, enabling lateral movement within the AWS environment via shared IAM permissions, S3 buckets, or VPC resources (GitHub Advisory, AWS Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires high privileges (both DescribeTrainingJob API access and S3 write permissions), which limits the attacker pool but does not eliminate insider threat or compromised-credential scenarios. The EPSS score is approximately 0.011–0.022%, indicating a low current probability of exploitation (GitHub Advisory). No threat actor attribution or CISA KEV catalog listing has been identified.
sagemaker:DescribeTrainingJob permissions and write access (s3:PutObject) to the target Training Job's S3 output location.aws sagemaker list-training-jobs to identify jobs using the remote functions feature of the SageMaker Python SDK.DescribeTrainingJob API for the target job (e.g., aws sagemaker describe-training-job --training-job-name <job-name>) and extract the HMAC signing key from the cleartext response elements (stored in environment variables returned by the API).aws s3 cp or equivalent S3 API calls.DescribeTrainingJob API calls, particularly from principals not normally associated with the Training Job; calls from unusual source IPs or at unusual times.PutObject events to the Training Job's S3 output location, especially from principals other than the SageMaker service role; modifications to serialized function result files (e.g., files with .pkl or similar extensions).DescribeTrainingJob API responses in older SDK versions (v3 < 3.2.0 or v2 < 2.256.0) — its presence in API responses is itself an indicator of a vulnerable configuration.AWS has released patched versions of the SageMaker Python SDK: v3.2.0 and v2.256.0, which remove the HMAC signing key from cleartext API responses. Upgrading to these versions immediately is the primary recommended remediation (AWS Security Bulletin, v2.256.0 Release, v3.2.0 Release). As interim mitigations, implement least-privilege IAM policies to restrict DescribeTrainingJob API access and S3 write permissions to only necessary principals, apply S3 bucket policies to restrict modifications to Training Job output locations, and enable S3 access logging and AWS CloudTrail to detect suspicious activity. Any forked or derivative code based on the affected SDK should also be patched (GitHub Advisory).
AWS published an official security bulletin (2026-004-AWS) on February 2, 2026, disclosing both CVE-2026-1777 and the related CVE-2026-1778 (Insecure TLS Configuration), and recommending immediate upgrade (AWS Security Bulletin). The advisory was also published to the GitHub Advisory Database and reviewed the same day. No significant independent researcher commentary or notable social media discussion beyond automated aggregation has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."