PT-2026-60841 · Amazon · Aws-Athena-Query-Federation
CVE-2026-12283
·
Published
2026-07-17
·
Updated
2026-07-17
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
aws-athena-query-federation versions 2022.20.1 through 2026.19.1
Description
Improper neutralization of special elements used in an SQL command within the Synapse connector of Amazon Athena Query Federation allows an authenticated remote user to execute injected read-only SQL queries. This can result in the retrieval of unintended data from the connected database by using a crafted table name.
Recommendations
Upgrade aws-athena-query-federation to version 2026.21.1 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Athena-Query-Federation