PT-2026-47035 · Amazon · Aws Advanced Go Wrapper For Amazon Aurora Postgresql
CVE-2026-11401
·
Published
2026-06-05
·
Updated
2026-07-30
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL versions prior to 2026-05-26
Description
An untrusted search path issue exists in the GlobalDatabasePlugin. This allows a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, such as
rds superuser. The escalation occurs through a crafted function created by the actor that executes when the target user connects to the cluster using the affected wrapper.Recommendations
Upgrade to the AWS Advanced Go Wrapper release 2026-05-26.
Exploit
Fix
LPE
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Advanced Go Wrapper For Amazon Aurora Postgresql