Improper Authorization in AWS Amplify API Category by Amazon
CVE-2026-108096

7.1HIGH

What is CVE-2026-108096?

The improperly implemented authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category allows authenticated remote users to craft queries that may expose records owned by other users within the same application. This vulnerability has been rectified in version 3.1.2 of @aws-amplify/graphql-index-transformer. Users are strongly advised to upgrade to the latest version and ensure any custom or derivative code includes the necessary patches to prevent unauthorized data access.

Affected Version(s)

aws-amplify/data-construct 0 < 1.17.4

aws-amplify/graphql-api-construct 1.4.0 <= 1.21.4

aws-amplify/graphql-index-transformer 2.2.0 < 3.1.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.