Executive Summary
Amazon Web Services (AWS) has published a security bulletin addressing CVE-2026-75210, an authentication session token reuse vulnerability within the Amazon S3 Express One Zone directory bucket architecture. Assigned a CVSS v3.1 base score of 8.9 (High/Critical), the flaw permitted unauthorized workloads operating within the same Availability Zone (AZ) subnet to replay ephemeral session tokens and access high-throughput object storage without active IAM authorization.
Introduced to deliver single-digit millisecond latency for compute-intensive workloads—such as AI model training checkpointing, financial algorithmic backtesting, and real-time advertising analytics—S3 Express One Zone replaces traditional per-request SigV4 authentication with an optimized regional CreateSession token exchange. CVE-2026-75210 undermined this session trust model in multi-tenant VPC environments.
Technical Root Cause: Flawed Enclave Binding in CreateSession Token Cache
To circumvent the cryptographic overhead of calculating HMAC-SHA256 SigV4 signatures on every single microsecond read/write operation, the S3 Express client SDK requests a 5-minute scoped session token via the s3express:CreateSession API. The returned token contains cryptographic session keys stored in an in-memory client cache.
Security researchers discovered that the backend storage cluster daemon verified the token signature but failed to validate that the incoming client IP address matched the VPC interface endpoint bound at token issuance. In shared EC2 clusters utilizing AWS Nitro Enclaves or containerized multi-tenant Kubernetes nodes, an attacker who captured an ephemeral session token from a shared network namespace could immediately replay it from an unrelated instance in the same AZ:
// Captured S3 Express Session Header:
x-amz-s3express-session-token: AQoDYXdzEJr...[Truncated]
x-amz-server-side-encryption: aws:kms
// Replayed Request from Unauthorized Pod:
PUT /checkpoint-epoch-42.pt HTTP/1.1
Host: model-weights--use1-az4--x-s3.s3express-use1-az4.amazonaws.com
x-amz-s3express-session-token: AQoDYXdzEJr...[Truncated]
// VULNERABLE: Accepted without verifying VPC endpoint identity!
Attack Surface: AI Model Checkpoint Theft & Data Poisoning
The impact of unauthorized S3 Express One Zone access is particularly acute for frontier artificial intelligence and quantitative finance operations:
- Proprietary Model Weight Exfiltration: Attackers can stream multi-gigabyte training checkpoints off S3 Express directory buckets at 100 Gbps speeds, exfiltrating proprietary neural network weights.
- Checkpoint Backdoor Injection: By overwriting model checkpoints during active distributed training runs, an adversary can poison model weights, embedding undetectable behavioral backdoors into production AI systems.
- Financial Tick Data Tampering: Modifying cached market microstructure tick data directly alters automated trading algorithm execution parameters.
Remediation & Cloud Architecture Playbook
AWS has updated the S3 Express One Zone authentication fleet to enforce cryptographically bound VPC Endpoint IDs (aws:sourceVpce) and client source IP validation on all session tokens. Cloud infrastructure teams should enforce the following controls:
- Update AWS SDKs: Ensure all applications utilizing S3 Express One Zone are compiled with AWS SDK versions released after October 2026.
- Enforce Explicit Bucket Policies: Add strict condition keys to S3 Express directory bucket policies restricting
s3express:CreateSessionexclusively to specific VPC Endpoint IDs:{ "Condition": { "StringEquals": { "aws:sourceVpce": "vpce-0123456789abcdef0" } } } - Separate Multi-Tenant Enclaves: Partition AI training clusters into dedicated VPC subnets and separate Availability Zones to eliminate shared network namespace risks.



