AI and data stack advisories

Severe, 6 weeks1905Projects319

1905 severe, 6 weeks · 319 projects

AWSAWS-2026-133

Improper authorization in query resolvers for SQL-backed models in AWS Amplify API...

AWS

CVE-2026-108096 · Published Oct 9, 2026

Medium6.5
No fix yet
AWS advisory

Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Impacted versions: - @aws-amplify/graphql-index-transformer >=2.2.0, =1.4.0, <1.21.4; - @aws-amplify/data-construct <1.17.4 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

SeverityOct 10Severity: Unrated to Medium
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD

More AWS advisories

All AWS