Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...
High8.0CVE-2026-11400 · Published Sep 22, 2026
Bulletin ID: 2026-039-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper: GHSA-r236-5pc3-3qcp Please email aws-s...
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Sep 26 | Severity: Unrated to High |
Details and references
Bulletin ID: 2026-039-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper: GHSA-r236-5pc3-3qcp Please email aws-security@amazon.com with any security questions or concerns. . "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-039-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-11400 and CVE-2026-11401 - Privilege Escalation in Aurora PostgreSQL using AWS Advanced JDBC Wrapper, AWS Advanced Go Wrapper Bulletin ID: 2026-039-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/05/2026 12:15 PM PDT Description: Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible with PostgreSQL. We identified CVE-2026-11400 (JDBC) and CVE-2026-11401 (Go), an issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. Impacted versions: AWS Advanced JDBC Wrapper >=3.0.0 and AWS Advanced Go Wrapper release 2026-04-06 Resolution: This issue has been addressed in the AWS Advanced JDBC Wrapper version 4.0.1 and the AWS Advanced Go Wrapper release 2026-05-26 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Remove the public schema from the search path. References: CVE-2026-11400 CVE-2026-11401 AWS Advanced JDBC Wrapper: GHSA-mhww-p97m-3368 AWS Advanced Go Wrapper: GHSA-r236-5pc3-3qcp Please email aws-security@amazon.com with any security questions or concerns. . {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-11401
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | High8.8 | No fix yet |
| Sep 22 | HTTPS Fallback to HTTP in Graph Explorer | Medium5.9 | No fix yet |
| Sep 22 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Critical9.0 | No fix yet |
| Sep 22 | Issue with HTTP/2 multi-frame request body inspection in AWS WAF | Critical9.8 | No fix yet |
| Sep 22 | Authenticated SQL injection in the metrics-service retention policy subsystem of... | High8.1 | No fix yet |
| Sep 22 | Excessive memory allocation in s2n-quic | Medium5.3 | No fix yet |