Description
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No customer action is required.
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized cross‑account query metadata exposure
Action: No action needed
AI Analysis

Impact

A missing authorization check in the request handling of Amazon Athena engine version 3 allowed an authenticated user to read query metadata—including AWS account identifiers and the text of SQL statements—from other AWS accounts. The vulnerability did not expose query results, credentials, or Amazon S3 data.

Affected Systems

The affected product is Amazon Athena, specifically the version 3 engine used for query handling. No specific internal sub‑products or version ranges are listed beyond this high‑level product designation.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation activity in the wild. Likely attack paths require an authenticated Athena user; the issue would allow limited metadata exposure but not data leaks or system compromise.

Generated by OpenCVE AI on October 7, 2026 at 21:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply least‑privilege IAM policies for Athena, limiting permissions to only those required for each user.
  • Enable and monitor CloudTrail or Athena audit logs to detect anomalous metadata access.
  • Configure AWS Config rules or CloudWatch to flag cross‑account IAM roles that could enable unauthorized metadata exposure.

Generated by OpenCVE AI on October 7, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No customer action is required.
Title Missing authorization checks in Amazon Athena engine version 3 request handling
First Time appeared Aws
Aws amazon Athena
Weaknesses CWE-424
CWE-862
CPEs cpe:2.3:a:aws:amazon_athena:n_a:*:*:*:*:*:*:*
Vendors & Products Aws
Aws amazon Athena
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Aws Amazon Athena
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-07T20:32:01.066Z

Reserved: 2026-10-07T19:18:38.898Z

Link: CVE-2026-107352

cve-icon Vulnrichment

Updated: 2026-10-07T20:31:56.094Z

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:15.373

Modified: 2026-10-07T21:17:15.373

Link: CVE-2026-107352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-424

    Improper Protection of Alternate Path

  • CWE-862

    Missing Authorization