CVE-2026-1777: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-1777 is an information disclosure vulnerability in the Amazon SageMaker Python SDK, where the ModelBuilder HMAC signing key is exposed in cleartext within the response elements of the DescribeTrainingJob API. Affected versions include SageMaker Python SDK v3 before v3.2.0 and v2 before v2.256.0. The vulnerability was disclosed on February 2, 2026, with patches released the same day (AWS Security Bulletin, GitHub Advisory). It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory).

Technical details

The root cause is classified under CWE-319 (Cleartext Transmission of Sensitive Information) and CWE-201 (Insertion of Sensitive Information Into Sent Data). The SageMaker SDK's remote functions feature uses a per-job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3; however, this key is stored in environment variables and returned in plaintext via the DescribeTrainingJob API response (AWS Security Bulletin, GitHub Advisory). An attacker with DescribeTrainingJob API permissions can retrieve the HMAC key, forge cloud-pickled (serialized) payloads with valid HMACs, and overwrite S3 objects at the Training Job's output location — bypassing integrity validation entirely. Exploitation requires two concurrent permissions: the ability to call DescribeTrainingJob and write access to the Training Job's S3 output location (GitHub Advisory).

Impact

Successful exploitation enables arbitrary code execution in the victim's Python process when the Training Job results are retrieved, as tampered payloads are deserialized without triggering integrity validation errors (GitHub Advisory). This can lead to compromise of training data, model poisoning, exposure of sensitive environment variables and AWS metadata, and unauthorized access to compute resources. In multi-tenant or shared S3 bucket environments, the exposed HMAC key can serve as a pivot point to compromise adjacent users' remote function workloads, enabling lateral movement within the AWS environment via shared IAM permissions, S3 buckets, or VPC resources (GitHub Advisory, AWS Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires high privileges (both DescribeTrainingJob API access and S3 write permissions), which limits the attacker pool but does not eliminate insider threat or compromised-credential scenarios. The EPSS score is approximately 0.011–0.022%, indicating a low current probability of exploitation (GitHub Advisory). No threat actor attribution or CISA KEV catalog listing has been identified.

Exploitation steps

  1. Obtain Required Permissions: Acquire AWS IAM credentials or a role with both sagemaker:DescribeTrainingJob permissions and write access (s3:PutObject) to the target Training Job's S3 output location.
  2. Identify Target Training Job: Enumerate SageMaker Training Jobs in the target AWS account using aws sagemaker list-training-jobs to identify jobs using the remote functions feature of the SageMaker Python SDK.
  3. Extract HMAC Key: Call the DescribeTrainingJob API for the target job (e.g., aws sagemaker describe-training-job --training-job-name <job-name>) and extract the HMAC signing key from the cleartext response elements (stored in environment variables returned by the API).
  4. Forge Malicious Payload: Using the extracted HMAC key, craft a malicious cloud-pickled (serialized) Python object containing arbitrary code. Sign the payload with the HMAC key to produce a valid HMAC signature that will pass integrity validation.
  5. Upload Malicious Artifact: Overwrite the legitimate serialized function result or argument in the Training Job's S3 output location with the forged payload using aws s3 cp or equivalent S3 API calls.
  6. Trigger Execution: Wait for or trigger the victim to retrieve the Training Job results via the SageMaker Python SDK. When the SDK deserializes the tampered payload, the embedded malicious code executes in the victim's Python process, achieving arbitrary code execution (GitHub Advisory, AWS Security Bulletin).

Indicators of compromise

  • AWS API Logs (CloudTrail): Unexpected or anomalous DescribeTrainingJob API calls, particularly from principals not normally associated with the Training Job; calls from unusual source IPs or at unusual times.
  • S3 Access Logs: Unexpected PutObject events to the Training Job's S3 output location, especially from principals other than the SageMaker service role; modifications to serialized function result files (e.g., files with .pkl or similar extensions).
  • Process Behavior: Unexpected child processes or network connections spawned from the Python process that retrieves Training Job results; unusual outbound connections from the SageMaker client environment.
  • Environment Variables: Presence of the HMAC key in DescribeTrainingJob API responses in older SDK versions (v3 < 3.2.0 or v2 < 2.256.0) — its presence in API responses is itself an indicator of a vulnerable configuration.
  • File System: Unexpected or recently modified serialized artifacts in the S3 output bucket associated with Training Jobs.

Mitigation and workarounds

AWS has released patched versions of the SageMaker Python SDK: v3.2.0 and v2.256.0, which remove the HMAC signing key from cleartext API responses. Upgrading to these versions immediately is the primary recommended remediation (AWS Security Bulletin, v2.256.0 Release, v3.2.0 Release). As interim mitigations, implement least-privilege IAM policies to restrict DescribeTrainingJob API access and S3 write permissions to only necessary principals, apply S3 bucket policies to restrict modifications to Training Job output locations, and enable S3 access logging and AWS CloudTrail to detect suspicious activity. Any forked or derivative code based on the affected SDK should also be patched (GitHub Advisory).

Community reactions

AWS published an official security bulletin (2026-004-AWS) on February 2, 2026, disclosing both CVE-2026-1777 and the related CVE-2026-1778 (Insecure TLS Configuration), and recommending immediate upgrade (AWS Security Bulletin). The advisory was also published to the GitHub Advisory Database and reviewed the same day. No significant independent researcher commentary or notable social media discussion beyond automated aggregation has been identified at this time.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management