CVE-2026-12283
Severity CVSS v4.0:
MEDIUM
Type:
CWE-89
SQL Injection
Publication date:
17/07/2026
Last modified:
20/07/2026
Description
Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax.<br />
<br />
<br />
<br />
Improper neutralization of special elements used in an SQL command in the Synapse connector in Amazon aws-athena-query-federation v2022.20.1 through v2026.19.1 might allow an authenticated remote user to execute injected read-only SQL queries that return unintended data from the connected database via a crafted table name.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to version v2026.21.1 or later.
Impact
Base Score 4.0
6.10
Severity 4.0
MEDIUM
Base Score 3.x
6.80
Severity 3.x
MEDIUM



