CVE-2026-77810
Received
Received - Intake
Neptune Data Exposure via Athena Federated Query in AWS
Vulnerability report for CVE-2026-77810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-21
Last updated on: 2026-08-21
Assigner: AMZN
Description
Description
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aws | athena_query_federation | From 2024.15.1 (inc) to 2026.28.1 (exc) |
| aws | athena_query_federation | 2026.30.1 |
| aws | aws_athena_query_federation | v2026.30.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-95 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval"). |