PT-2026-30219 · Amazon · Amazon Athena Odbc Driver+1

CVE-2026-35560

·

Published

2026-04-03

·

Updated

2026-04-03

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Amazon Athena ODBC driver versions prior to 2.1.0.0
Description Improper certificate validation in the identity provider connection components may allow a man-in-the-middle threat actor to intercept authentication credentials. This occurs due to insufficient default transport security when connecting to external identity providers. This issue does not affect connections made directly to Athena.
Recommendations Update to version 2.1.0.0.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35560

Affected Products

Amazon Athena Odbc Driver
Athena Odbc