PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35560 Amazon CVE debrief

The Amazon Athena ODBC driver before version 2.1.0.0 has a critical vulnerability CVE-2026-35560 due to improper certificate validation in its identity provider connection components. This issue might allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers. The vulnerability has a CVSS score of 9.1 and is considered critical. Organizations should prioritize upgrading to the latest version to mitigate the risk of authentication credential interception by a man-in-the-middle threat actor.

Vendor
Amazon
Product
Amazon Athena ODBC driver
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Organizations using Amazon Athena ODBC driver versions before 2.1.0.0 should prioritize upgrading to the latest version to mitigate the risk of authentication credential interception by a man-in-the-middle threat actor. This is particularly important for organizations that rely on external identity providers for authentication.

Technical summary

The Amazon Athena ODBC driver before version 2.1.0.0 does not properly validate certificates when connecting to identity providers, potentially allowing man-in-the-middle attacks to intercept authentication credentials. This vulnerability is specific to connections with external identity providers and does not affect connections with Athena. The issue can be remediated by upgrading to version 2.1.0.0 of the driver. It is essential to review and update configurations for connections with external identity providers and monitor for any suspicious activity related to authentication credentials.

Defensive priority

High priority should be given to upgrading the Amazon Athena ODBC driver to version 2.1.0.0 or later to prevent potential man-in-the-middle attacks that could intercept authentication credentials. Additionally, organizations should review and update configurations for connections with external identity providers and monitor for any suspicious activity related to authentication credentials.

Recommended defensive actions

  • Upgrade Amazon Athena ODBC driver to version 2.1.0.0 or later
  • Review and update configurations for connections with external identity providers
  • Monitor for any suspicious activity related to authentication credentials
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-03T21:17:12.073Z and was last modified on 2026-07-24T21:10:00.143Z. The vulnerability has been analyzed and has a CVSS score of 9.1. There is limited information available about the specific attack vectors or exploits used in the wild. However, it is known that the vulnerability affects the Amazon Athena ODBC driver before version 2.1.0.0 and could allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35560 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35560

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35560 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35560

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-013-aws/

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch, Product

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.