Missing Authorization Checks in Amazon Athena Engine Affecting AWS
CVE-2026-107352

6.3MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107352?

The vulnerability in Amazon Athena's engine version 3 involved missing authorization checks which permitted an authenticated user to access limited query metadata, including AWS account identifiers and SQL statement text from other AWS accounts. Importantly, this issue did not impact query results, credentials, or Amazon S3 data. AWS responded promptly, resolving the vulnerability on September 1, 2026, and confirmed that no customer metadata was compromised. Customers are advised that no action is required on their part.

Affected Version(s)

Amazon Athena

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Act Security
.