Skip to content
AWSAWS-2026-039

Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...

High8.0CVE-2026-11400 · Published Sep 22, 2026

Bulletin ID:  2026-039-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper:  GHSA-r236-5pc3-3qcp Please email  aws-s...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to High
Details and references

Bulletin ID:  2026-039-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper:  GHSA-r236-5pc3-3qcp Please email  aws-security@amazon.com  with any security questions or concerns. . "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-039-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-11400 and CVE-2026-11401 - Privilege Escalation in Aurora PostgreSQL using AWS Advanced JDBC Wrapper, AWS Advanced Go Wrapper Bulletin ID:  2026-039-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper:  GHSA-r236-5pc3-3qcp Please email  aws-security@amazon.com  with any security questions or concerns. . {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
NVD
Also known as
CVE-2026-11401

More AWS advisories

All AWS
Advisory
Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
High8.8Sep 22
HTTPS Fallback to HTTP in Graph Explorer
Medium5.9Sep 22
Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
Critical9.0Sep 22
Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Critical9.8Sep 22
Authenticated SQL injection in the metrics-service retention policy subsystem of...
High8.1Sep 22
Excessive memory allocation in s2n-quic
Medium5.3Sep 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.