Issue with Athena Federated Query Clickhouse Connector
UnratedCVE-2026-75910 · Published Aug 20, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-084-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/20/2026 13:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-75910. Incorrect privilege assignment in the ClickHouse connector deployment template before the v2026.17.1 release could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. Impacted versions: < V2026.17.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 25 | Consent bypass in Strands Agents Tools python_repl tool | Unrated | No fix yet |
| Aug 21 | Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards | Unrated | No fix yet |
| Aug 21 | Issue with Athena Federated Query Neptune Connector | Unrated | No fix yet |
| Aug 21 | Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236... | Unrated | No fix yet |
| Aug 18 | Issue with Amazon ion-java - Memory-amplification denial of service | Unrated | No fix yet |
| Aug 18 | Uncontrolled resource consumption in OpenSearch Dashboards capabilities route | Unrated | No fix yet |