CRITICAL🇵🇱 Wersja polska

CVE-2026-35560

CVSS 9.1v4.0pub. 2026-04-03upd. 2026-07-24

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.

🤖 AI Analysis
How it works

The error results from insufficient default transport security (CWE-295 — improper certificate validation) in components responsible for connecting with identity providers. An attacker positioned on the network communication path (man-in-the-middle) can impersonate a legitimate identity provider server, because the driver does not properly verify the TLS certificate of the server. As a result, it is possible to intercept transmitted authentication credentials. The vulnerability affects only connections with external identity providers — direct connections to Amazon Athena are not exposed.

Impact

An attacker can intercept user authentication credentials (e.g., tokens, passwords) transmitted to external identity providers, which may lead to unauthorized access to resources protected by these credentials.

Mitigation & patch

Update the Amazon Athena ODBC driver to version 2.1.0.0 or later. Installation packages for Linux, macOS (Intel and ARM), and Windows systems are available in the vendor's references (AWS Security Bulletin 2026-013).

Who is affected

Amazon Athena ODBC Driver in versions before 2.1.0.0 on Linux, macOS (Intel and ARM), and Microsoft Windows platforms — only in configurations using external identity providers.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Amazon Athena Odbc

    APP
    Amazon
    < 2.1.0.0
  • Apple macOS

    OS
    Apple
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP