Incorrect Privilege Assignment in Amazon Athena Federated Query Connector
CVE-2026-75910
7.1HIGH
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-75910?
The Amazon Athena Federated Query connector features a misconfiguration that allows authenticated remote users to access AWS Secrets Manager secrets. By manipulating the connector's connection string to point to an unrelated secret housed in a database endpoint they control, these users can inadvertently transmit sensitive secrets, posing a significant security risk. Users are encouraged to upgrade to version v2026.17.1 or later, or to redeploy the connector with a specified non-empty SecretNamePrefix to mitigate this issue.
Affected Version(s)
Athena Federated Query Clickhouse Connector deployment template 0 < 2026.17.1
