PT-2026-47034 · Amazon · Aws Advanced Jdbc Wrapper
CVE-2026-11400
·
Published
2026-06-05
·
Updated
2026-07-17
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL versions prior to 4.0.1
Description
An untrusted search path issue exists in the GlobalDatabasePlugin. This allows a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including
rds superuser. The attack is performed via a crafted function created by the actor that executes when the target user connects to the cluster through an affected wrapper.Recommendations
Upgrade to AWS Advanced JDBC Wrapper version 4.0.1.
Exploit
Fix
LPE
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Advanced Jdbc Wrapper