CVE-2026-105811 - Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS
Bulletin ID: 2026-126-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/06/2026 13:00 PM PDT
Description:
QnABot on AWS is a sample solution of a multi-channel, multi-language conversational interface (chatbot) that responds to your customer's questions, answers, and feedback. We identified CVE-2026-105811 in the optional Amazon Q Business Lambda hook sample of QnABot on AWS. The Amazon Q Business Lambda hook sample (q-business-lambda-hook) is an optional integration sample included in the QnABot on AWS repository. It requires separate, manual deployment and additional setup; it is not deployed automatically with QnABot. Customers who have not deployed this sample are not affected and do not need to take action.
Authorization bypass through a user-controlled key in the sample included with QnABot on AWS versions 7.0.0 through 7.4.5 might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account.
To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.
Impacted versions: >=7.0.0, <7.4.6
Resolution:
This issue has been addressed in QnABot on AWS version v7.4.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix. No action is required for customers who do not currently use the Amazon Q Business Lambda hook sample stack.
Workarounds:
There is no workaround available.
References:
Acknowledgement:
We would like to thank Oren Yomtov for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.