PT-2026-96855 · Amazon · Amazon-Connect-Salesforce-Lambda

·

CVE-2026-94384

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Amazon amazon-connect-salesforce-lambda versions prior to 5.26
Description Missing authorization in the Amazon Connect Salesforce integration allows an IAM principal with lambda:InvokeFunction permission to escalate privileges. The sfExecuteAWSService() function dispatches caller-supplied parameters to privileged AWS service APIs without validating if the caller is authorized for the requested operation. This allows a lower-privileged identity to act as a confused deputy—a security situation where a privileged entity is tricked by a less privileged entity into performing an action—to execute AWS API operations that their own IAM policy explicitly denies, potentially leading to unauthorized access or modification of AWS resources.
Recommendations Upgrade to version 5.26 or later. Delete or disable the sfExecuteAWSService() function. If the sfExecuteAWSService() function must be retained, restrict its invocation to the intended IAM user only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94384
GHSA-C9J2-QJFV-MM4P

Affected Products

Amazon-Connect-Salesforce-Lambda