Improper Authorization in AWS Amplify API Category by Amazon
CVE-2026-108096
7.1HIGH
Key Information:
- Vendor
Aws
- Status
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-108096?
The improperly implemented authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category allows authenticated remote users to craft queries that may expose records owned by other users within the same application. This vulnerability has been rectified in version 3.1.2 of @aws-amplify/graphql-index-transformer. Users are strongly advised to upgrade to the latest version and ensure any custom or derivative code includes the necessary patches to prevent unauthorized data access.
Affected Version(s)
aws-amplify/data-construct 0 < 1.17.4
aws-amplify/graphql-api-construct 1.4.0 <= 1.21.4
aws-amplify/graphql-index-transformer 2.2.0 < 3.1.2
