CVE-2026-75910
Received Received - Intake

Privilege Escalation in Amazon Athena Federated Query

Vulnerability report for CVE-2026-75910, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: AMZN

Description

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-21
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
amazon aws-athena-query-federation 2026.17.1
aws aws-athena-query-federation to 2026.17.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75910 is an incorrect privilege assignment flaw in the ClickHouse connector deployment template for Amazon Athena Federated Query before version v2026.17.1. An authenticated remote user can exploit this by manipulating the connector's connection string to redirect AWS Secrets Manager secrets to an endpoint they control.

Detection Guidance

Check the version of your aws-athena-query-federation connectors. If it is below v2026.17.1, the system is vulnerable. Commands to check include: aws serverlessrepo list-application-versions --application-id arn:aws:serverlessrepo:us-east-1:292517250237:applications/aws-athena-query-federation or inspect the connector deployment template for incorrect privilege assignments.

Impact Analysis

This vulnerability allows an attacker with low privileges to read sensitive AWS Secrets Manager secrets in your account. The attacker could gain access to database credentials, API keys, or other confidential data stored in Secrets Manager.

Mitigation Strategies

Upgrade to aws-athena-query-federation connectors version v2026.17.1 or later. Alternatively, redeploy the connector with a non-empty SecretNamePrefix value in the deployment template to prevent unauthorized secret exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75910. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart