Back to vendor advisories
AWS Security BulletinsCVE-2026-107352

CVE-2026-107352 - Missing authorization checks in Amazon Athena engine version 3 request handling

Severity not listed 1 CVE Published Oct 7, 2026 at 8:19 PM UTC

Summary

Bulletin ID: 2026-128-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/07/2026 13:00 PM PDT

Description:

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amazon S3 data were not affected. No customer action is required.

Resolution:

This issue was addressed service-side on September 1, 2026.

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed.

CVEs in this advisory 1

Updates

  1. Published by AWS

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.