Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-77810: Athena queries can expose Neptune connector Lambda settings

CVE-2026-77810 · published 13 days ago
Summary

If you let users run Athena federated queries against Neptune, they could see internal details of the Lambda function that runs the connector. This could reveal configuration information that should stay private. Upgrade the Athena federation library to version 2026.30.1 or newer to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
aws athena federated query neptune connector <= 2026.28.1
Original advisory text
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue...
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Severity
9.4 Critical
CVSS 3.1: 9.9 (MITRE)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published21 Aug 2026
Updated30 Aug 2026
First seen21 Aug 2026
Sources
CVE-2026-77810 · MITRE
Monitor software like this
Free during beta