Summary
Bulletin ID: 2026-128-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/07/2026 13:00 PM PDT
Description:
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amazon S3 data were not affected. No customer action is required.
Resolution:
This issue was addressed service-side on September 1, 2026.
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed.
CVEs in this advisory 1
Updates
- Published by AWS
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.