Privilege Escalation in Aurora PostgreSQL instance using AWS-JDBC Wrapper
High8.0CVE-2025-12967 · Published Nov 10, 2025
### Description of Vulnerability: An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5 or greater ### Source of Vulnerability Report: Allistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com) ### Affected products & versions: AWS JDBC Wrapper < 2.6.5 ### Platforms: MacOS/Windows/Linux
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| software.amazon.jdbc:aws-advanced-jdbc-wrapper Maven | < 2.6.5 | 2.6.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-470
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 8 | Defense in depth enhancement for region parameter value in AWS SDK for .NET V4 | Low3.7 | 4.0.3.3 |
| Jan 8 | Defense in depth enhancement for region parameter value in AWS SDK for C++ | Low3.7 | 1.11.685 |
| Jan 8 | Defense in depth enhancement for region parameter value in AWS SDK for JavaScript v3 | Low3.7 | 4.4.0+ |
| Dec 172025 | Key Commitment issue in S3 Encryption Client | Medium5.3 | 3.368.0 |
| Dec 172025 | Key Commitment issue in S3 Encryption Client | Medium5.3 | 1.208.0 |
| Dec 172025 | Key Commitment issue in S3 Encryption Client | Medium5.3 | 1.11.712 |