Improper XML External Entity Protection in AWS Advanced JDBC Wrapper
CVE-2026-18061

6MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
11 September 2026

What is CVE-2026-18061?

A vulnerability in the RemoteQueryCachePlugin of AWS Advanced JDBC Wrapper versions 3.3.0 through 4.2.0 allows an individual with write access to exploit the shared cache infrastructure. This can lead to the disclosure of sensitive information, such as database credentials and IAM role information, by utilizing crafted XML data within cached column values. Users are advised to upgrade to version 4.3.0 or later to mitigate this issue.

Affected Version(s)

AWS Advanced JDBC Wrapper 3.3.0 <= 4.2.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.