PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108096 AWS CVE debrief

AWS Amplify API Category Improper Authorization Vulnerability. The @aws-amplify/graphql-index-transformer package before 3.1.2 has an improper authorization vulnerability in query resolvers for SQL-backed models. This might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Defenders of AWS Amplify API Category deployments should assess exposure and prioritize remediation. The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4.

Vendor
AWS
Product
aws-amplify/graphql-index-transformer
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders of AWS Amplify API Category deployments should assess exposure and prioritize remediation. Roles including security teams, DevOps, and developers who use AWS Amplify API Category should verify their deployments and update affected packages.

Why it matters

CVE-2026-108096 is a medium-severity vulnerability in AWS Amplify API Category that may allow authenticated remote users to read unauthorized records. Defenders should assess exposure, prioritize remediation, and verify affected deployments.

  • Authenticated remote users may be able to read records owned by other users
  • Requires verification of affected versions and deployments
  • Remediation involves upgrading to patched versions and redeploying backend
  • Exposure assessment and inventory checks are necessary

Technical summary

The @aws-amplify/graphql-index-transformer package in AWS Amplify API Category before 3.1.2 has an improper authorization vulnerability in query resolvers for SQL-backed models. This might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. The vulnerability is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4. Defenders should assess exposure, prioritize remediation, and verify affected deployments.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade to @aws-amplify/graphql-index-transformer 3.1.2 or later
  • Upgrade to @aws-amplify/data-construct 1.17.4 or later
  • Upgrade to @aws-amplify/graphql-api-construct 1.21.4 or later
  • Review and patch any forked or derivative code
  • Redeploy backend with updated packages

Evidence notes

The CVE record and source item provide details on the improper authorization vulnerability in AWS Amplify API Category. The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, and @aws-amplify/graphql-api-construct 1.21.4.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108096 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108096

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108096 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108096

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108096.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2

    Supplemental source - patch, release-notes

  • Source reference

    Unverified legacy reference

    URL: https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4

    Supplemental source - patch, release-notes

  • Source reference

    Unverified legacy reference

    URL: https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4

    Supplemental source - patch, release-notes

  • Source reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-133-aws/

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/aws-amplify/amplify-category-api/security/advisories/GHSA-69c4-mvf5-5xm3

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.