PT-2026-96855 · Amazon · Amazon-Connect-Salesforce-Lambda
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Amazon amazon-connect-salesforce-lambda versions prior to 5.26
Description
Missing authorization in the Amazon Connect Salesforce integration allows an IAM principal with
lambda:InvokeFunction permission to escalate privileges. The sfExecuteAWSService() function dispatches caller-supplied parameters to privileged AWS service APIs without validating if the caller is authorized for the requested operation. This allows a lower-privileged identity to act as a confused deputy—a security situation where a privileged entity is tricked by a less privileged entity into performing an action—to execute AWS API operations that their own IAM policy explicitly denies, potentially leading to unauthorized access or modification of AWS resources.Recommendations
Upgrade to version 5.26 or later.
Delete or disable the
sfExecuteAWSService() function.
If the sfExecuteAWSService() function must be retained, restrict its invocation to the intended IAM user only.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon-Connect-Salesforce-Lambda