PT-2026-60841 · Amazon · Aws-Athena-Query-Federation

CVE-2026-12283

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions aws-athena-query-federation versions 2022.20.1 through 2026.19.1
Description Improper neutralization of special elements used in an SQL command within the Synapse connector of Amazon Athena Query Federation allows an authenticated remote user to execute injected read-only SQL queries. This can result in the retrieval of unintended data from the connected database by using a crafted table name.
Recommendations Upgrade aws-athena-query-federation to version 2026.21.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12283
GHSA-43CR-4635-MFJP

Affected Products

Aws-Athena-Query-Federation