PT-2026-79118 · Amazon · Amazon Athena Federated Query Clickhouse Connector

·

CVE-2026-75910

·

Published

2026-08-20

·

Updated

2026-08-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Amazon Athena Federated Query ClickHouse connector versions prior to v2026.17.1
Description Incorrect privilege assignment in the deployment template allows an authenticated remote user to read arbitrary AWS Secrets Manager secrets within the deploying account. An attacker can achieve this by directing the connector's connection string toward an unrelated secret and a database endpoint under their control, which leads the connector to transmit the secret to that endpoint.
Recommendations Upgrade to aws-athena-query-federation connectors version v2026.17.1 or later. Redeploy the connector using the current template and provide a non-empty SecretNamePrefix value.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75910
GHSA-VMJG-C6WV-WJM9

Affected Products

Amazon Athena Federated Query Clickhouse Connector