Description
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.
Published: 2026-08-20
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect privilege assignment in the ClickHouse connector deployment template for Amazon Athena Federated Query. A flaw allows an authenticated user to read any AWS Secrets Manager secret in the deploying account. The weakness is a relativized permission grant (CWE-266). If an attacker controls the connector’s connection string, they can point it at an arbitrary secret and a database endpoint under their control, causing the connector to transmit that secret to the attacker’s endpoint, thus exposing sensitive data.

Affected Systems

This issue affects users of the AWS Athena Federated Query ClickHouse Connector deployment template before version v2026.17.1. Any deployment using the older template is vulnerable unless a forked or derivative version has been patched.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity. EPSS data is not available, so the probability of exploitation is uncertain, but the flaw is not listed in the CISA KEV catalog. The attack requires an authenticated remote user who can modify or redeploy the connector; thus the attack vector is limited to legitimate users with appropriate deployment privileges. Organizations should assess whether their deployment practices allow such users or depend on customer-managed credentials to mitigate the risk.

Generated by OpenCVE AI on August 21, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the connector to aws-athena-query-federation v2026.17.1 or later to receive the fix for the privilege assignment issue.
  • Ensure any forked or derivative versions of the connector incorporate the same patch changes found in the official release.
  • If an upgrade is not immediately possible, redeploy the connector with the current template and supply a non-empty SecretNamePrefix value to restrict secret exposure.

Generated by OpenCVE AI on August 21, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.
Title Incorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment template
First Time appeared Aws
Aws athena Federated Query Clickhouse Connector Deployment Template
Weaknesses CWE-266
CPEs cpe:2.3:a:aws:athena_federated_query_clickhouse_connector_deployment_template:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws athena Federated Query Clickhouse Connector Deployment Template
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aws Athena Federated Query Clickhouse Connector Deployment Template
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-20T20:09:53.343Z

Reserved: 2026-08-18T15:04:52.415Z

Link: CVE-2026-75910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T20:17:46.937

Modified: 2026-08-20T20:17:46.937

Link: CVE-2026-75910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment