CVE-2026-11400

Severity CVSS v4.0:
HIGH
Type:
CWE-426 Untrusted Search Path
Publication date:
05/06/2026
Last modified:
05/06/2026

Description

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through an affected wrapper.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to AWS Advanced JDBC Wrapper version 4.0.1.