CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category
Bulletin ID: 2026-133-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/09/2026 11:00 AM PDT
Description:
AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.
Impacted versions:
- @aws-amplify/graphql-index-transformer >=2.2.0, <3.1.2;
- @aws-amplify/graphql-api-construct >=1.4.0, <1.21.4;
- @aws-amplify/data-construct <1.17.4
Resolution:
This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 (included in @aws-amplify/data-construct 1.17.4 and @aws-amplify/graphql-api-construct 1.21.4). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.
Workarounds:
No workarounds are available.
References:
Please email aws-security@amazon.com with any security questions or concerns.