Improper XML External Entity Protection in AWS Advanced JDBC Wrapper
CVE-2026-18061
6MEDIUM
What is CVE-2026-18061?
A vulnerability in the RemoteQueryCachePlugin of AWS Advanced JDBC Wrapper versions 3.3.0 through 4.2.0 allows an individual with write access to exploit the shared cache infrastructure. This can lead to the disclosure of sensitive information, such as database credentials and IAM role information, by utilizing crafted XML data within cached column values. Users are advised to upgrade to version 4.3.0 or later to mitigate this issue.
Affected Version(s)
AWS Advanced JDBC Wrapper 3.3.0 <= 4.2.0
