CVE-2026-11401
Severity CVSS v4.0:
HIGH
Type:
CWE-426
Untrusted Search Path
Publication date:
05/06/2026
Last modified:
05/06/2026
Description
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through the affected wrapper.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to the AWS Advanced Go Wrapper release 2026-05-26
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.00
Severity 3.x
HIGH



