CRITICAL🇵🇱 Wersja polska

CVE-2026-35561

CVSS 9.1v4.0pub. 2026-04-03upd. 2026-07-24

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0.

🤖 AI Analysis
How it works

The Amazon Athena ODBC driver implements a browser-based authentication mechanism that contains insufficient session protection controls. Due to gaps in authentication security controls (CWE-862 — Missing Authorization), a network attacker can intercept or hijack an active authentication session. The attack does not require the attacker to possess any credentials or require user interaction, although it is associated with certain environmental requirements (AT:P — specific attack conditions required).

Impact

An attacker can intercept or hijack the victim's authentication session, thereby gaining unauthorized access to Amazon Athena data and resources with high impact on data confidentiality and integrity.

Mitigation & patch

Amazon Athena ODBC driver must be immediately updated to version 2.1.0.0 or later. Installation packages for Linux (RPM), macOS Intel, and macOS ARM are available at the addresses indicated in the AWS security bulletin (2026-013-aws). Detailed release information is available in the official ODBC driver v2 documentation.

Who is affected

Amazon Athena ODBC driver in all versions prior to 2.1.0.0, running on Linux, Apple macOS (Intel and ARM), and Microsoft Windows systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Amazon Athena Odbc

    APP
    Amazon
    < 2.1.0.0
  • Apple macOS

    OS
    Apple
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP