Skip to content
AWSAWS-2026-059

Issue with Athena Federated Query Synapse Connector

UnratedCVE-2026-12283 · Published Jul 17, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-12283 . A user with access to an Azure Synapse account can create a table with a specially crafted name that, when queried through the Athena Synapse connector, could result in unintended data being returned. Impacted versions:   versions >= v2022.20.1 (released on 5/19/2022) AND  versions Resolution: This issue has been addressed in AWS Athena Query Federation version v2026.21.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Verify that there are no tables that can be subject to SQL injection in the Synapse database. If you allow Sy...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-12283 . A user with access to an Azure Synapse account can create a table with a specially crafted name that, when queried through the Athena Synapse connector, could result in unintended data being returned. Impacted versions:   versions >= v2022.20.1 (released on 5/19/2022) AND  versions Resolution: This issue has been addressed in AWS Athena Query Federation version v2026.21.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Verify that there are no tables that can be subject to SQL injection in the Synapse database. If you allow Synapse tables to be created programmatically, you should sanitize the input. References: CVE-2026-12283 GHSA-43cr-4635-mfjp Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-059-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-12283 - Issue with Athena Federated Query Synapse Connector Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-12283 . A user with access to an Azure Synapse account can create a table with a specially crafted name that, when queried through the Athena Synapse connector, could result in unintended data being returned. Impacted versions:   versions >= v2022.20.1 (released on 5/19/2022) AND  versions Resolution: This issue has been addressed in AWS Athena Query Federation version v2026.21.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Verify that there are no tables that can be subject to SQL injection in the Synapse database. If you allow Synapse tables to be created programmatically, you should sanitize the input. References: CVE-2026-12283 GHSA-43cr-4635-mfjp Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Path traversal and arbitrary file write in the workflow linters of...
UnratedJul 17
Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
UnratedJul 16
OS command injection in jsii-diff in AWS jsii
UnratedJul 15
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
UnratedJul 15
aws-load-balancer-controller: insufficient isolation
Medium5.8Jul 14
AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
UnratedJul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.