PatchSiren cyber security CVE debrief
CVE-2026-35560 Amazon CVE debrief
The Amazon Athena ODBC driver before version 2.1.0.0 has a critical vulnerability CVE-2026-35560 due to improper certificate validation in its identity provider connection components. This issue might allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers. The vulnerability has a CVSS score of 9.1 and is considered critical. Organizations should prioritize upgrading to the latest version to mitigate the risk of authentication credential interception by a man-in-the-middle threat actor.
- Vendor
- Amazon
- Product
- Amazon Athena ODBC driver
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Organizations using Amazon Athena ODBC driver versions before 2.1.0.0 should prioritize upgrading to the latest version to mitigate the risk of authentication credential interception by a man-in-the-middle threat actor. This is particularly important for organizations that rely on external identity providers for authentication.
Technical summary
The Amazon Athena ODBC driver before version 2.1.0.0 does not properly validate certificates when connecting to identity providers, potentially allowing man-in-the-middle attacks to intercept authentication credentials. This vulnerability is specific to connections with external identity providers and does not affect connections with Athena. The issue can be remediated by upgrading to version 2.1.0.0 of the driver. It is essential to review and update configurations for connections with external identity providers and monitor for any suspicious activity related to authentication credentials.
Defensive priority
High priority should be given to upgrading the Amazon Athena ODBC driver to version 2.1.0.0 or later to prevent potential man-in-the-middle attacks that could intercept authentication credentials. Additionally, organizations should review and update configurations for connections with external identity providers and monitor for any suspicious activity related to authentication credentials.
Recommended defensive actions
- Upgrade Amazon Athena ODBC driver to version 2.1.0.0 or later
- Review and update configurations for connections with external identity providers
- Monitor for any suspicious activity related to authentication credentials
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-03T21:17:12.073Z and was last modified on 2026-07-24T21:10:00.143Z. The vulnerability has been analyzed and has a CVSS score of 9.1. There is limited information available about the specific attack vectors or exploits used in the wild. However, it is known that the vulnerability affects the Amazon Athena ODBC driver before version 2.1.0.0 and could allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers.
Official resources
-
CVE-2026-35560 CVE record
CVE.org
-
CVE-2026-35560 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T21:17:12.073Z and has not been modified since then.