← Terug naar overzicht

CVE-2026-77810 describes a vulnerability in the AWS Athena Federated Query Neptune connector where an authorized user could gain unauthorized access to Lambda function properties supplying compute for the connector. This represents a privilege escalation/information disclosure risk within the AWS cloud environment. The flaw affects the aws-athena-query-federation component and could expose sensitive configuration or credential data stored in Lambda properties. AWS has issued a security bulletin (2026-087) addressing this issue. The remediation requires upgrading to aws-athena-query-federation version v2026.30.1 or later. A GitHub security advisory (GHSA-v7c2-5wfg-qg44) has also been published alongside the fix release.

Affected products

  • AWS Lambda
  • Amazon Athena Federated Query
  • Amazon Neptune
  • aws-athena-query-federation

Related CVE's

  • CVE-2026-77810

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access