CVE-2026-77810 describes a vulnerability in the AWS Athena Federated Query Neptune connector where an authorized user could gain unauthorized access to Lambda function properties supplying compute for the connector. This represents a privilege escalation/information disclosure risk within the AWS cloud environment. The flaw affects the aws-athena-query-federation component and could expose sensitive configuration or credential data stored in Lambda properties. AWS has issued a security bulletin (2026-087) addressing this issue. The remediation requires upgrading to aws-athena-query-federation version v2026.30.1 or later. A GitHub security advisory (GHSA-v7c2-5wfg-qg44) has also been published alongside the fix release.