PatchSiren cyber security CVE debrief
CVE-2026-108096 AWS CVE debrief
AWS Amplify API Category Improper Authorization Vulnerability. The @aws-amplify/graphql-index-transformer package before 3.1.2 has an improper authorization vulnerability in query resolvers for SQL-backed models. This might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Defenders of AWS Amplify API Category deployments should assess exposure and prioritize remediation. The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4.
- Vendor
- AWS
- Product
- aws-amplify/graphql-index-transformer
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders of AWS Amplify API Category deployments should assess exposure and prioritize remediation. Roles including security teams, DevOps, and developers who use AWS Amplify API Category should verify their deployments and update affected packages.
Why it matters
CVE-2026-108096 is a medium-severity vulnerability in AWS Amplify API Category that may allow authenticated remote users to read unauthorized records. Defenders should assess exposure, prioritize remediation, and verify affected deployments.
- Authenticated remote users may be able to read records owned by other users
- Requires verification of affected versions and deployments
- Remediation involves upgrading to patched versions and redeploying backend
- Exposure assessment and inventory checks are necessary
Technical summary
The @aws-amplify/graphql-index-transformer package in AWS Amplify API Category before 3.1.2 has an improper authorization vulnerability in query resolvers for SQL-backed models. This might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. The vulnerability is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4. Defenders should assess exposure, prioritize remediation, and verify affected deployments.
Defensive priority
Medium
Recommended defensive actions
- Upgrade to @aws-amplify/graphql-index-transformer 3.1.2 or later
- Upgrade to @aws-amplify/data-construct 1.17.4 or later
- Upgrade to @aws-amplify/graphql-api-construct 1.21.4 or later
- Review and patch any forked or derivative code
- Redeploy backend with updated packages
Evidence notes
The CVE record and source item provide details on the improper authorization vulnerability in AWS Amplify API Category. The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108096 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108096
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108096 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108096
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108096.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2
Supplemental source - patch, release-notes
-
Source reference
Unverified legacy reference
URL: https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4
Supplemental source - patch, release-notes
-
Source reference
Unverified legacy reference
URL: https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4
Supplemental source - patch, release-notes
-
Source reference
Unverified legacy reference
URL: https://aws.amazon.com/security/security-bulletins/2026-133-aws/
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/aws-amplify/amplify-category-api/security/advisories/GHSA-69c4-mvf5-5xm3
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.