{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/aws-sagemaker/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS SageMaker"],"_cs_severities":["high"],"_cs_tags":["cloud","aws","privilege-escalation","sagemaker"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries targeting AWS environments can leverage Amazon SageMaker to escalate privileges by exploiting the interaction between SageMaker resource creation actions and IAM role assignment. When creating resources like Notebook Instances, Training Jobs, Processing Jobs, AutoML Jobs, or Pipelines, a caller must possess the \u003ccode\u003eiam:PassRole\u003c/code\u003e permission to associate an execution role with the new resource.\u003c/p\u003e\n\u003cp\u003eIf an attacker has sufficient permissions to initiate these SageMaker resources and holds a broad \u003ccode\u003eiam:PassRole\u003c/code\u003e grant, they can pass a more privileged role - or a role from a different account - to the resource. The resulting SageMaker resource then executes code under the context of the assigned role, effectively allowing the attacker to perform actions that the original caller could not. This technique is particularly dangerous as it utilizes legitimate, expected functionality to bridge security boundaries. Monitoring for unusual associations between IAM principals and execution roles is essential for detecting potential credential abuse or unauthorized privilege escalation within AWS MLOps workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to achieve code execution as a more privileged IAM role, leading to unauthorized data access, persistence, or broader administrative control within the AWS account. This risk is especially critical in production MLOps environments where high-privilege service roles are frequently utilized for legitimate automated data processing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement the detection logic to identify the first time an IAM principal uses a specific \u003ccode\u003eroleArn\u003c/code\u003e for SageMaker resource creation within a 7-day window.\u003c/li\u003e\n\u003cli\u003eReview the \u003ccode\u003eaws.cloudtrail.user_identity.arn\u003c/code\u003e of the principal performing the action and investigate the \u003ccode\u003eroleArn\u003c/code\u003e passed in \u003ccode\u003eaws.cloudtrail.request_parameters\u003c/code\u003e for unauthorized privilege escalation.\u003c/li\u003e\n\u003cli\u003eConstrain \u003ccode\u003eiam:PassRole\u003c/code\u003e permissions using IAM policy conditions (such as \u003ccode\u003eiam:PassedToService\u003c/code\u003e) to ensure that principals can only pass narrowly scoped, approved execution roles to SageMaker.\u003c/li\u003e\n\u003cli\u003eRotate or restrict credentials for any principal identified using an unexpected or overly privileged execution role.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T09:23:25Z","date_published":"2026-07-31T09:23:25Z","id":"https://feed.craftedsignal.io/briefs/2026-07-aws-sagemaker-privesc/","summary":"An adversary with SageMaker resource-creation rights and broad iam:PassRole permissions can escalate privileges by passing highly privileged IAM roles to SageMaker notebook instances, training, processing, or pipeline jobs.","title":"AWS SageMaker Execution Role Privilege Escalation via PassRole","url":"https://feed.craftedsignal.io/briefs/2026-07-aws-sagemaker-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS SageMaker","version":"https://jsonfeed.org/version/1.1"}