Authorization Bypass in Amazon QnABot on AWS by AWS
CVE-2026-105811

7.1HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105811?

An authorization bypass vulnerability exists within the optional Amazon Q Business Lambda hook sample in QnABot on AWS. This vulnerability allows authenticated remote users to gain unauthorized access to read arbitrary Amazon S3 objects in the associated AWS account. The issue stems from a user-controlled key in the Lambda hook sample, which is not deployed automatically with QnABot, thus only affecting those who manually implement this optional feature. To mitigate this vulnerability, users must update their QnABot on AWS stack to version 7.4.6 or later and redeploy the Amazon Q Business Lambda hook sample stack, as simply updating the main stack does not address the issue.

Affected Version(s)

qnabot-on-aws 7.0.0 < 7.4.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.