CVE-2026-12283

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
17/07/2026
Last modified:
20/07/2026

Description

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax.<br /> <br /> <br /> <br /> Improper neutralization of special elements used in an SQL command in the Synapse connector in Amazon aws-athena-query-federation v2022.20.1 through v2026.19.1 might allow an authenticated remote user to execute injected read-only SQL queries that return unintended data from the connected database via a crafted table name.<br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to version v2026.21.1 or later.