PT-2026-47035 · Amazon · Aws Advanced Go Wrapper For Amazon Aurora Postgresql

CVE-2026-11401

·

Published

2026-06-05

·

Updated

2026-07-30

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL versions prior to 2026-05-26
Description An untrusted search path issue exists in the GlobalDatabasePlugin. This allows a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, such as rds superuser. The escalation occurs through a crafted function created by the actor that executes when the target user connects to the cluster using the affected wrapper.
Recommendations Upgrade to the AWS Advanced Go Wrapper release 2026-05-26.

Exploit

Fix

LPE

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11401
GHSA-R236-5PC3-3QCP
GO-2026-5601
OPENSUSE-SU-2026:21483-1

Affected Products

Aws Advanced Go Wrapper For Amazon Aurora Postgresql