← All Advisories

CVE-2026-94384

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-94384

Key Details

CVECVE-2026-94384
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsamazon amazon-connect-salesforce-lambda
Classified asCWE-862 (Missing Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
amazonamazon-connect-salesforce-lambda
SubsystemsGeneral OT
SectorsMultiple

What to Know

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation.

To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only. (NVD)

What to Do

Monitor amazon's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-94384
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-94384