CVE-2026-83551
Cleartext HMAC key stored in SageMaker pipeline decorators enables forged signatures and code execution.
- CVSS 8.5
- 312
- Cryptographic
- Remote
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.
- CWE
- 312
- CVSS base score
- 8.5
- Published
- 2026-09-01
- OWASP
- A02 Cryptographic Failures
- Orthogonal defect classification
- Assignment
- Code defect classification
- Incorrect Assignment
- Category
- Cryptographic
- Subcategory
- Cryptographic Implementation Error
- Accessibility scope
- Remote
- Impact
- Arbitrary Code Execution
- Affected component
- Amazon SageMaker Python SDK
- Fixed by upgrading
- Yes
Solution
Upgrade the Amazon SageMaker Python SDK to v3.11.0 or newer (or v2.256.0 or newer).
Vulnerable code sample
import json
from sagemaker.workflow.pipeline import Pipeline
from sagemaker.workflow.steps import step, remote
@step
def my_step(input_uri: str):
# VULNERABLE: stores HMAC signing key in cleartext step metadata
signing_key = "hmac-secret-key-0123"
payload = {"input_uri": input_uri, "signing_key": signing_key}
return json.dumps(payload)
pipeline = Pipeline(
name="example-pipeline",
steps=[my_step],
description="Demo pipeline with vulnerable step"
)Patched code sample
import json
from sagemaker.workflow.pipeline import Pipeline
from sagemaker.workflow.steps import step, remote
from sagemaker.secrets_manager import SecretsManager
secrets = SecretsManager()
@step
def my_step(input_uri: str):
# FIX: retrieve HMAC key from Secrets Manager instead of embedding it
signing_key = secrets.get_secret_value(SecretId="my-hmac-key")["SecretString"]
payload = {"input_uri": input_uri, "signing_key": signing_key}
return json.dumps(payload)
pipeline = Pipeline(
name="example-pipeline",
steps=[my_step],
description="Demo pipeline with patched step"
)Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202683551,
title = {{Cleartext HMAC key stored in SageMaker pipeline decorators enables forged signatures and code execution.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-83551},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-83551/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
