CVE-2026-12283 Details
Description
Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. Improper neutralization of special elements used in an SQL command in the Synapse connector in Amazon aws-athena-query-federation v2022.20.1 through v2026.19.1 might allow an authenticated remote user to execute injected read-only SQL queries that return unintended data from the connected database via a crafted table name. To remediate this issue, users should upgrade to version v2026.21.1 or later.
A vulnerability in the Amazon Athena Query Federation Synapse connector, affecting versions v2022.20.1 prior to v2026.19.1, allows authenticated remote users to execute injected read-only SQL queries. This could result in unintended data being retrieved from the connected Azure Synapse database. The issue arises from improper handling of special elements in SQL commands, which could be exploited by crafting a table name that, when queried through Athena, executes the injected SQL and returns sensitive data.
Users should upgrade to Amazon Athena Query Federation version v2026.21.1 or later. Instructions for upgrading can be found in the release notes on the AWS Athena Query Federation GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | New CVE Received | AMZN |
| Jul 17, 2026 | CVE Modified | CISA-ADP |