Impact
The Neptune connector allows a privileged user to inject code through a Gremlin query passthrough, enabling manipulation of the Lambda compute environment. This code injection can expose or alter properties of the Lambda function, potentially allowing execution of arbitrary code or unauthorized data access. The vulnerability is a CWE‑95 type input validation flaw that directly compromises confidentiality, integrity, and availability of the compute resources.
Affected Systems
AWS Athena Federated Query Neptune Connector is affected. Any deployment using the connector prior to version v2026.30.1 is vulnerable; the patch is available starting with v2026.30.1.
Risk and Exploitability
The CVSS score of 9.4 denotes a critical severity. EPSS information is not available, but the lack of KEV listing does not reduce the threat. The likely attack vector is remote, via an Athena federated query that an authenticated user can submit; this inference is based on the description stating that a user with Neptune access can exploit the issue.
OpenCVE Enrichment