CVE-2026-35561
Amazon’s Athena ODBC driver had weak authentication controls in its browser‑based login flow. Versions before 2.1.0.0 could let an attacker intercept or hijack a user’s authentication session. The flaw could let a malicious actor gain unauthorized access to Athena data.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Amazon Athena ODBC driver, versions earlier than 2.1.0.0, used on Windows, Linux, or macOS by database administrators and developers.
Real-world impact
An attacker could hijack a user’s authentication session and then run queries or access data in Athena without permission, potentially exposing sensitive information.
Why this severity
The CVSS score of 9.1 reflects that the flaw is easy to exploit (low complexity, no privileges, no user interaction) and can completely compromise confidentiality and integrity of Athena data.
What to do about it
- 01Upgrade the Amazon Athena ODBC driver to version 2.1.0.0 or later.
- 02Restart any applications or services that use the driver.
NVD-referenced vendor advisory
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- aws.amazon.com/security/security-bulletins…vendor advisory
- docs.aws.amazon.com/athena/latest/ug/odbc-v2-dr…release notes
- downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux…patchproduct
- downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/I…patchproduct
- downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/a…patchproduct
- downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windo…patchproduct