CVE-2026-11400
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-426
Ruta de búsqueda no confiable
Fecha de publicación:
05/06/2026
Última modificación:
05/06/2026
Descripción
*** Pendiente de traducción *** An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through an affected wrapper.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to AWS Advanced JDBC Wrapper version 4.0.1.
Impacto
Puntuación base 4.0
8.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.00
Gravedad 3.x
ALTA



