CVE-2026-108096
Received Received - Intake

Improper Authorization in AWS Amplify GraphQL Index Transformer

Vulnerability report for CVE-2026-108096, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: AMZN

Description

Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2 (included in @aws-amplify/data-construct 1.17.4 https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4 and @aws-amplify/graphql-api-construct 1.21.4 https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4 ). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
AWS aws-amplify/graphql-index-transformer 2.2.0
AWS aws-amplify/graphql-api-construct 1.4.0
AWS aws-amplify/data-construct 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization flaw in AWS Amplify's API Category. It affects SQL-backed models and allows authenticated remote users to read records owned by other users in the same application by crafting malicious queries. The issue exists in query resolvers generated by the @aws-amplify/graphql-index-transformer library.

Detection Guidance

To detect this vulnerability, check the versions of @aws-amplify/graphql-index-transformer, @aws-amplify/graphql-api-construct, and @aws-amplify/data-construct in your AWS Amplify API Category. If using versions 2.2.0 to less than 3.1.2, 1.4.0 to less than 1.21.4, or below 1.17.4 respectively, the system is vulnerable. Run commands like 'npm list @aws-amplify/graphql-index-transformer' to verify versions.

Impact Analysis

An attacker could exploit this to access sensitive data belonging to other users, potentially leading to unauthorized information disclosure. This includes reading records, files, or other confidential data stored in the application if it uses SQL data sources with owner or group authorization rules.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating compliance requirements for data protection such as GDPR (privacy) and HIPAA (health information). Unauthorized access to user data may result in legal penalties, loss of trust, and failure to meet regulatory standards for data security and confidentiality.

Mitigation Strategies

Upgrade to the latest versions of @aws-amplify/graphql-index-transformer (3.1.2 or higher), @aws-amplify/data-construct (1.17.4 or higher), and @aws-amplify/graphql-api-construct (1.21.4 or higher). Ensure any modified code incorporates the fixes and redeploy your backend.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108096. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart