Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0.
The Amazon Athena ODBC driver implements a browser-based authentication mechanism that contains insufficient session protection controls. Due to gaps in authentication security controls (CWE-862 — Missing Authorization), a network attacker can intercept or hijack an active authentication session. The attack does not require the attacker to possess any credentials or require user interaction, although it is associated with certain environmental requirements (AT:P — specific attack conditions required).
An attacker can intercept or hijack the victim's authentication session, thereby gaining unauthorized access to Amazon Athena data and resources with high impact on data confidentiality and integrity.
Amazon Athena ODBC driver must be immediately updated to version 2.1.0.0 or later. Installation packages for Linux (RPM), macOS Intel, and macOS ARM are available at the addresses indicated in the AWS security bulletin (2026-013-aws). Detailed release information is available in the official ODBC driver v2 documentation.
Amazon Athena ODBC driver in all versions prior to 2.1.0.0, running on Linux, Apple macOS (Intel and ARM), and Microsoft Windows systems.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAmazon Athena Odbc
APPAmazon< 2.1.0.0Apple macOS
OSAppleall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP