Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xidian University

#41535of 56,333
7.1Total CVSS
Vulnerabilities · 1
PT-2026-79118
7.1
2026-08-20
Amazon · Amazon Athena Federated Query Clickhouse Connector · CVE-2026-75910
**Name of the Vulnerable Software and Affected Versions** Amazon Athena Federated Query ClickHouse connector versions prior to v2026.17.1 **Description** Incorrect privilege assignment in the deployment template allows an authenticated remote user to read arbitrary AWS Secrets Manager secrets within the deploying account. An attacker can achieve this by directing the connector's connection string toward an unrelated secret and a database endpoint under their control, which leads the connector to transmit the secret to that endpoint. **Recommendations** Upgrade to aws-athena-query-federation connectors version v2026.17.1 or later. Redeploy the connector using the current template and provide a non-empty `SecretNamePrefix` value.