CVE 7.1 HIGH

Insecure Deserialization in Amazon Braket SDK Job Results Processing_CVE-2026-9291

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Description

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.



We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.

Basic Information

ID CVE-2026-9291
Source AMZN
Published May 22, 2026 at 18:12
Modified May 22, 2026 at 18:17

Affected Product

Vendor AWS
Product Amazon Braket Python SDK
Version 1.10.0
Affected Versions AWS Amazon Braket Python SDK 1.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.