Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Telegram Desktop Bug CVE-2023-34399 Exposes Chat Messages
September 15, 2026
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP With $159 DDR5 Device
September 15, 2026
Critical Gitea RCE Vulnerability Under Active Exploitation
September 15, 2026
Home/Vulnerabilities/Critical Marimo RCE (CVE-2024-XXXX) Lets Attackers Steal AWS Credentials
Vulnerabilities

Critical Marimo RCE (CVE-2024-XXXX) Lets Attackers Steal AWS Credentials

Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-39987, in the Marimo notebook platform has been exploited. Attackers leveraged the flaw to steal AWS credentials and gain...

Marcus Rodriguez
Marcus Rodriguez
September 15, 2026 3 Min Read
2 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability, CVE-2026-39987, in the Marimo notebook platform has been exploited.
  • Attackers leveraged the flaw to steal AWS credentials and gain SSH access to bastion hosts.
  • The vulnerability affects Marimo versions up to 0.20.4 and has been patched in version 0.23.0.
  • The attack chain, from initial compromise to SSH authentication, was observed to take only eight seconds.

Cybersecurity researchers have documented active exploitation of a severe remote code execution vulnerability within the Marimo notebook platform. This flaw, tracked as CVE-2026-39987, enabled threat actors to rapidly exfiltrate AWS credentials and establish SSH access to a bastion host, completing the entire sequence in a mere eight seconds.

Table Of Content

  • Key Takeaways
  • Rapid Credential Theft and Lateral Movement
  • What You Should Do

The incident was brought to light by the Sysdig Threat Research Team. Their analysis revealed that the pre-authentication RCE vulnerability impacted Marimo versions up to and including 0.20.4. A corrective update was subsequently released, with the issue resolved in Marimo version 0.23.0.

Marimo is an open-source reactive Python notebook platform widely adopted by developers, data scientists, and machine learning teams. Given that such notebook servers often operate in close proximity to cloud workloads, sensitive datasets, API tokens, and development tools, a successful compromise can grant attackers significant access to critical environments.

The root cause of the vulnerability lay in Marimo’s terminal WebSocket endpoint, which failed to adequately enforce authentication protocols. This oversight allowed an attacker to establish a WebSocket connection and gain an interactive shell, operating with the same privileges as the user running the Marimo process, without requiring any valid credentials.

Rapid Credential Theft and Lateral Movement

In the observed attack scenario, the threat actor utilized bespoke tooling rather than relying on AI or large language model agents. Despite this manual approach, the operator demonstrated exceptional speed in navigating the compromised environment, moving at what Sysdig described as “machine speed.”

Sysdig found that the attacker initiated a new WebSocket session and, within a mere eight seconds, successfully authenticated via SSH to a downstream bastion host.

Upon gaining initial access to the Marimo server, the attacker immediately began searching for cloud credentials. These credentials were discovered both within the host environment and the application’s Redis backend. Leveraging the stolen AWS credentials, the threat actor then queried AWS Secrets Manager.

The request to Secrets Manager yielded an SSH private key. Without delay, the attacker utilized this key to authenticate to an internet-accessible SSH bastion host, also known as a jump server. Bastion hosts are typically deployed as controlled gateways, providing administrators with secure access to systems residing within private cloud networks. Their compromise can thus offer attackers a direct conduit into internal network resources.

This rapid pivot from credential theft to bastion host access underscores the critical importance of strictly scoped cloud permissions. A notebook instance should ideally not possess broad permissions to retrieve secrets that are unrelated to its designated workload. In this specific incident, credentials available on the compromised Marimo host provided access to an SSH key, facilitating lateral movement into another segment of the environment.

The incident also serves as a stark reminder of the inherent risks associated with exposed developer and machine learning infrastructure. While teams often deploy notebook servers rapidly for experimental purposes, these deployments frequently retain access to vital resources such as AWS services, source code repositories, datasets, model-provider credentials, and internal systems. A single unauthenticated service can, therefore, become a critical entry point for a much broader cloud breach.

What You Should Do

  • Organizations utilizing Marimo should immediately upgrade to version 0.23.0 or any subsequent secure version.
  • Security teams must identify and secure all public-facing Marimo deployments, disabling or protecting any unnecessary terminal endpoints, and ensuring that all WebSocket services mandate proper authentication.
  • AWS administrators should conduct a thorough review of IAM permissions assigned to notebook workloads, paying particular attention to access granted to AWS Secrets Manager. Credentials should strictly adhere to the principle of least privilege, preventing access to unrelated SSH keys, production secrets, or high-value access tokens.
  • Teams are advised to rotate all AWS credentials, SSH keys, API tokens, and any other secrets that may have been exposed on vulnerable instances.
  • Implement enhanced monitoring for unusual requests to Secrets Manager, unexpected credential usage patterns, new SSH authentications to bastion hosts, and rapid sequences of cloud API activity immediately following application access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

AI Agents Steal Thousands of Credentials in 6 Hours

Next Post

Critical Gitea RCE Vulnerability Under Active Exploitation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Abuse VSSAdmin to Steal NTDS.dit, Delete Windows Backups
September 15, 2026
Top 10 Cloud Infrastructure Entitlement Management (CIEM) Tools for 2026
September 15, 2026
Top Container Security Tools for 2024
September 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us