Authorization Bypass in Amazon QnABot on AWS by AWS
CVE-2026-105811
7.1HIGH
What is CVE-2026-105811?
An authorization bypass vulnerability exists within the optional Amazon Q Business Lambda hook sample in QnABot on AWS. This vulnerability allows authenticated remote users to gain unauthorized access to read arbitrary Amazon S3 objects in the associated AWS account. The issue stems from a user-controlled key in the Lambda hook sample, which is not deployed automatically with QnABot, thus only affecting those who manually implement this optional feature. To mitigate this vulnerability, users must update their QnABot on AWS stack to version 7.4.6 or later and redeploy the Amazon Q Business Lambda hook sample stack, as simply updating the main stack does not address the issue.
Affected Version(s)
qnabot-on-aws 7.0.0 < 7.4.6
