{{#include ../../../../banners/hacktricks-training.md}}
If an attacker manages to obtain a presigned URL for a SageMaker resource, they can access it without any further authentication. The permissions and access level will depend on the role associated with the resource:
{{#ref}} ../../aws-privilege-escalation/aws-sagemaker-privesc/README.md {{#endref}}
{{#include ../../../../banners/hacktricks-training.md}}