Description
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Published: 2026-08-21
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Neptune connector allows a privileged user to inject code through a Gremlin query passthrough, enabling manipulation of the Lambda compute environment. This code injection can expose or alter properties of the Lambda function, potentially allowing execution of arbitrary code or unauthorized data access. The vulnerability is a CWE‑95 type input validation flaw that directly compromises confidentiality, integrity, and availability of the compute resources.

Affected Systems

AWS Athena Federated Query Neptune Connector is affected. Any deployment using the connector prior to version v2026.30.1 is vulnerable; the patch is available starting with v2026.30.1.

Risk and Exploitability

The CVSS score of 9.4 denotes a critical severity. EPSS information is not available, but the lack of KEV listing does not reduce the threat. The likely attack vector is remote, via an Athena federated query that an authenticated user can submit; this inference is based on the description stating that a user with Neptune access can exploit the issue.

Generated by OpenCVE AI on August 21, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AWS Athena Federated Query Neptune Connector to version v2026.30.1 or later.
  • Restrict IAM permissions for users allowed to submit Athena federated queries, limiting ability to craft injection queries.
  • Monitor Athena query logs for unexpected or malformed Gremlin query patterns and investigate any anomalies.

Generated by OpenCVE AI on August 21, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Title Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector
First Time appeared Aws
Aws athena Federated Query Neptune Connector
Weaknesses CWE-95
CPEs cpe:2.3:a:aws:athena_federated_query_neptune_connector:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws athena Federated Query Neptune Connector
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Aws Athena Federated Query Neptune Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-27T16:46:27.538Z

Reserved: 2026-08-21T13:59:15.911Z

Link: CVE-2026-77810

cve-icon Vulnrichment

Updated: 2026-08-27T16:08:45.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-21T20:16:45.530

Modified: 2026-08-27T20:18:39.727

Link: CVE-2026-77810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:14:42Z

Weaknesses
  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')