Security Policy Bypass in DuckDB AWS Extension
CVE-2026-58139

6MEDIUM

Key Information:

Vendor

Duckdb

Vendor
CVE Published:
3 August 2026

What is CVE-2026-58139?

The DuckDB AWS extension is susceptible to a security policy bypass vulnerability that allows users with SQL execution permissions to extract sensitive AWS credentials. By invoking the load_aws_credentials function with the redact_secret parameter set to false, attackers can bypass the database-wide policy designed to prevent the exposure of unredacted secrets. This vulnerability can lead to the unauthorized retrieval of critical AWS credential information, such as access keys and session tokens, which are highly dangerous in environments where AWS roles and credential chains are in use.

Affected Version(s)

duckdb-aws 0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mehmet Ince (@mdisec)
.