Back to vendor advisories
AWS Security BulletinsCVE-2026-108096

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

Severity not listed 1 CVE Published Oct 9, 2026 at 6:13 PM UTC

Summary

Bulletin ID: 2026-133-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/09/2026 11:00 AM PDT

Description:

AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.

Impacted versions:

- @aws-amplify/graphql-index-transformer >=2.2.0, <3.1.2;

- @aws-amplify/graphql-api-construct >=1.4.0, <1.21.4;

- @aws-amplify/data-construct <1.17.4

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by AWS

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.