Vulnerability Description
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-036-aws/
- https://github.com/amazon-braket/amazon-braket-sdk-python/releases/tag/v1.117.0
- https://github.com/amazon-braket/amazon-braket-sdk-python/security/advisories/GH
FAQ
What is CVE-2026-9291?
CVE-2026-9291 is a vulnerability with a CVSS score of 7.1 (HIGH). Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve ar...
How severe is CVE-2026-9291?
CVE-2026-9291 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9291?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.