CVE-2026-35558 Details
Description
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated authentication. To remediate this issue, users should upgrade to version 2.1.0.0.
A vulnerability exists in the Amazon Athena ODBC driver, specifically in versions prior to 2.1.0.0, within the authentication components. This vulnerability could allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that the driver processes during user-initiated authentication. The issue has been addressed in version 2.1.0.0, which is available for Windows, Linux, and macOS.
Users are advised to upgrade to the Amazon Athena ODBC driver version 2.1.0.0. This version can be downloaded from the Amazon Athena ODBC 2.x driver release notes page. For Windows, the driver is available as an MSI installer. For Linux, it can be downloaded as an RPM package. macOS users can choose between an ARM or Intel package.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon athena odbc | < 2.1.0.0 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | AMZN |