CVE-2026-107352 - Missing authorization checks in Amazon Athena engine version 3 request handling
Bulletin ID: 2026-128-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/07/2026 13:00 PM PDT
Description:
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amazon S3 data were not affected. No customer action is required.
Resolution:
This issue was addressed service-side on September 1, 2026.
Workarounds:
No workaround is available.
References:
Acknowledgement:
We would like to thank Oren Yomtov of Act Security for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.